GITHUBEXPLOIT 7.8 HIGH

exp_baddial_9158EF99-80E6-5568-8BF3-FC4DAB14A820

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

expbaddial XTC 儿童手表表盘插件远程代码执行漏洞 PoC 漏洞概述 XTC i3launcher 从外部存储 /sdcard/xtc/dial/compose/element/ 加载 .pl 格式的 DEX 插件时: - 零签名校验 - 零完整性检查 - 直接在 UID 1000 system 进程中执行 - 继承 i3launcher 的全部 70+ 系统权限 任意 APP 或具有存储写入权限的攻击者可通过替换 .pl 文件实现系统级代码执行。 复现步骤 前置条件 - XTC...
Visit Original Source

Basic Information

ID 9158EF99-80E6-5568-8BF3-FC4DAB14A820
Published May 24, 2026 at 09:01
Modified May 24, 2026 at 09:11

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.