Passer au contenu
  • Blog
  • Contacter Rbcafe
  • Portfolio
    • À propos de Rbcafe
    • Par Rbcafe
    • Galerie
    • Unity
    • Site Internet
    • Design Web
  • Sécurité
    • Archives CVE
    • CVE
    • Swag
  • Logiciels
    • Cryptext
    • Hash
    • Host3r
    • Inventaire
    • Outguess
    • Review Sherlock
    • Time Up
    • Tracking
    • Voix
    • Worktime
    • Yang
    • Zen
  • Support
    • Demander du support
    • Documentation
    • Confidentialité
    • Devis
Rbcafe
  • Blog
  • Contacter Rbcafe
  • Portfolio
    • À propos de Rbcafe
    • Par Rbcafe
    • Galerie
    • Unity
    • Site Internet
    • Design Web
  • Sécurité
    • Archives CVE
    • CVE
    • Swag
  • Logiciels
    • Cryptext
    • Hash
    • Host3r
    • Inventaire
    • Outguess
    • Review Sherlock
    • Time Up
    • Tracking
    • Voix
    • Worktime
    • Yang
    • Zen
  • Support
    • Demander du support
    • Documentation
    • Confidentialité
    • Devis
Rbcafe
CVE : CVE-2025-10184

ID: CVE-2025-10184
Status: PUBLISHED
Source: rapid7
JSON: MITRE

Temporalité

Publié: 2025-09-23
Dernière modification: 2025-09-23

CVSS

Score: 8.2 (High)
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Version: 4.0

Carte CIA (CVSS) Score 3.33 [ C : 10 ] [ I : 0 ] [ A : 0 ]
CWE
CWE-862 Missing Authorization (CWE-862) CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Description

The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provided Telephony provider without permission, user interaction, or consent. The user is also not notified that SMS data is being accessed. This could lead to sensitive information disclosure and could effectively break the security provided by SMS-based Multi-Factor Authentication (MFA) checks.

The root cause is a combination of missing permissions for write operations in several content providers (com.android.providers.telephony.PushMessageProvider, com.android.providers.telephony.PushShopProvider, com.android.providers.telephony.ServiceNumberProvider), and a blind SQL injection in the update method of those providers.

Tags
CWE-862 Missing AuthorizationCWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')exploitssvcVulnogram 0.2.0
Produits affectés
OnePlus OxygenOS (11.*, 12.*, 13.*, 14.*, 15.*)
Références
https://www.rapid7.com/blog/post/cve-2025-10184-oneplus-oxygenos-telephony-provider-permission-bypass-not-fixed/ https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/bltd4b7439a28b6c866/68d168a6930d015d43a6b588/CVE-2025-10184_PoC.zip
Rbcafe ©2026 | About | Privacy Policy | X | GitHub | Mac App Store | Telegram / 0x3C159845943CDA7937D05034D87E916C5BA00DA9