In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction.
The error results from improper permission verification (CWE-280 — Improper Handling of Insufficient Permissions or Privileges). The permission control mechanism in the SDK is weak enough that an attacker or malicious application can gain access to resources and data that should be protected. The vulnerability is remotely exploitable (network vector), does not require user interaction, though it requires high-level permissions (PR:H). The scope of the attack extends beyond the component in which the vulnerability occurs (Scope: Changed).
An attacker can gain unauthorized access to internal application information, resulting in a breach of confidentiality, integrity, and data availability. The vulnerability may lead to the disclosure of sensitive data stored by the SDK without the user's knowledge and consent.
Patches available from the manufacturer should be applied in accordance with references published on the OPPO Security page (https://security.oppo.com/en/noticeDetail?notice_only_key=NOTICE-1759867611954552832). It is recommended to update the SDK to the version indicated by the manufacturer as secure.
OPPO Usercenter Credit Software Development Kit — specific versions indicated in the manufacturer's references (OPPO Security Notice page).
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HOppo Usercenter Credit Software Development Kit
APPOppoall versions
Related vulnerabilities
Command Injection w OPPO Quick Game Engine umożliwiający RCE
Privilege Escalation w Oppo ColorOS — dynamiczne ładowanie usług SDK backupu
RCE w Oppo QualityProtect — wykonanie dowolnych poleceń systemowych
Podatność zapisu dowolnych plików z uprawnieniami systemowymi w Oppo OvoiceManager
ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.