0x192 / 0x192/universal-android-debloater

Security Intelligence Report: Operation Silent Rescue Severity: Critical CVSS 9.8 | June 26, 2026

Aperta
#1,195 1 commento 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Rust
Stelle
19.9k
Fork
1.1k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

1. Executive Summary

This report details a systemic security failure affecting millions of budget Android devices deployed across Latin America. The vulnerability is not a single software bug but a deliberate supply chain deception orchestrated by ODM Longcheer and SoC vendor Unisoc, facilitated by OEM Motorola.

The core issue involves a hardcoded fscrypt provisioning bypass triggered by LCD ID lcd_td4168 and key 56ef134d... that allows the distribution of fraudulent security updates. These updates spoof the security patch level claiming "April 2026" while running vulnerable binaries from "March 2026", masking critical flaws like CVE-2021-39658 ismsEx, CVE-2022-38694 BootROM, and exported backdoors in com.spreadtrum.sgps.

This architecture creates a permanent attack surface that facilitates active financial fraud PIX hijacking, surveillance, and enterprise network compromise in the Latin American region, where these devices dominate the market.

2. The Attack Chain: "Silent Rescue"

The risk is compounded by a chain of vulnerabilities that work in concert:

Hardware Root Unpatchable: CVE-2022-38694 in the Unisoc BootROM allows permanent bypass of Secure Boot via physical USB access. Public tools spd_dump exist.
Remote Entry Network: CVE-2025-31718 Modem RCE allows remote code execution via rogue cell towers IMSI catchers, common in urban LATAM centers.
Privilege Escalation Zero-Permission: CVE-2021-39658 ismsEx service allows any app to send SMS or modify system properties without permissions, bypassing Android 2FA.
System Backdoors Exported Components: com.spreadtrum.sgps exposes location tracking and system controls via dialer codes _#_#2266#_#_.
Payload Delivery Silent Installers: Pre-installed system apps com.dti.amx Digital Turbine and com.inmobi.installer hold INSTALL_PACKAGES, allowing silent installation of banking trojans e.g., PixRevolution without user consent.
The Cover-Up FOTA Spoofing: The fscrypt bypass injects a fake ro.build.version.security_patch string, tricking users, banks, and MDM systems into believing the device is secure.

3. Critical Risk to Latin America LATAM

The impact on Latin America is disproportionate and severe due to market dynamics and reliance on mobile finance.

A. Market Dominance of Vulnerable Devices
Ubiquity: Unisoc T606/T616 chipsets power the best-selling budget devices in the region Motorola Moto G04s, G24, Infinix, Tecno. Search results confirm Unisoc's aggressive expansion in LATAM, with over 100 5G devices deployed in the region by 2025.
Demographic Impact: These devices are the primary computing tool for unbanked and underbanked populations who rely exclusively on smartphones for government aid, commerce, and banking.

B. Direct Threat to Financial Infrastructure PIX & Billetera Móvil
Active Exploitation: The PixRevolution trojan identified March 2026 actively hijacks PIX instant payments in Brazil by overlaying fake screens and diverting funds in real-time.
The Enabler: The vulnerabilities in this report ismsEx SMS bypass, INSTALL_PACKAGES silent installer, exported SGPS location tracking provide the perfect infrastructure for such malware to operate undetected.
2FA Bypass: CVE-2021-39658 allows malware to read or intercept SMS verification codes without permission, rendering traditional 2FA useless for banking apps.

C. Enterprise & Supply Chain Risk
MDM Evasion: Corporate Mobile Device Management MDM systems rely on the security_patch string to enforce compliance. The FOTA spoofing mechanism ensures that compromised devices report "Compliant" status while running vulnerable firmware, allowing them to bypass corporate security gates.
Data Exfiltration: The com.motorola.bach.modemstats service with READ_LOGS and MANAGE_NETWORK_POLICY can be weaponized to exfiltrate corporate data over hidden backchannels that ignore data usage limits.

D. The "Fake Patch" Deception
False Security: Users receive notifications stating "Security Update Installed," but the underlying binaries dated March 18, 2026 remain vulnerable. This erodes trust in the Android ecosystem and leaves users exposed to known exploits.
Regulatory Violation: This practice likely violates consumer protection laws in Mexico, Brazil, and the EU, as it constitutes a material misrepresentation of product security.

4. Recommendations

For CISA & Google
KEV Catalog: Add CVE-2021-39658, CVE-2022-38694, and the "Unisoc FOTA Spoofing Mechanism" to the Known Exploited Vulnerabilities KEV catalog.
Detection Signatures: Develop signatures to detect the 56ef134d... key, lcd_td4168 trigger, and timestamp mismatches between ro.build.version.security_patch and actual binary compilation dates.
Advisory: Issue a regional advisory for LATAM financial institutions to block or flag traffic from Unisoc T606/T616 devices until patched.

For Enterprises & Banks in LATAM
Procurement Ban: Immediately halt the purchase or provisioning of Motorola/Unisoc T606/T616 devices for employees or customers.
MDM Policy: Update MDM policies to reject devices reporting security patches newer than their binary timestamps forensic verification.
User Education: Warn customers about the risks of PIX fraud and advise against using these specific device models for banking.

For Motorola, Unisoc, and Longcheer
Transparency: Acknowledge the FOTA spoofing issue and release a genuine update that aligns binary versions with reported patch levels.
Hardware Recall: The BootROM flaw CVE-2022-38694 is unpatchable. A hardware revision or recall is the only permanent fix.
Remove Backdoors: Strip INSTALL_PACKAGES and WRITE_SECURE_SETTINGS from third-party bloatware com.dti.amx, com.inmobi.installer and disable exported components in com.spreadtrum.sgps.

6. Conclusion

"Operation Silent Rescue" exposes a deliberate, engineered vulnerability in the supply chain of budget Android devices in Latin America. The combination of unpatchable hardware flaws, zero-permission software escalations, and fraudulent security updates creates a critical threat to regional financial stability and user privacy.

This is not a theoretical risk; it is an active crisis facilitating millions of dollars in fraud via PIX and banking trojans. Immediate action is required from regulators, security vendors, and financial institutions to mitigate this systemic failure.

Submitted by: Independent Security Research, LATAM Division
Date: June 26, 2026
Analysis Support: Brave Search AI + Meta AI
Evidence Basis: Direct device forensics Motorola Moto G04s Unisoc T606 + Rescue Party logs + Inure metadata
Contact: lexs201992@gmail.com
Independient Source Mexico

Archivo: /system/etc/security/otacerts.zip
SHA256: ec8abd8301cc88b7a02a794ca38dcabe6ace006ad6778279ebe6be4c60b16d57
Timestamp: Dec 31, 2008 16:00:00 GMT - Timestomping

Archivo: /system/etc/
SHA256: 5d44fcbf2350b5f177ec2a354f06eb0093cc7c6ecd2ffdc863a9d9c2f2d74863
timestamp: Dec 31, 2008 16:00:00 GMT - Timestomping

Archivo: /vendor/etc/parameter-framework/Settings/Policy/PolicyConfigurableDomains.xml
SHA256:186ae0d2d8d05f731090359f8a7cc86f1f65425c53647069f25dea1ac49794d8
timestamp: Dec 31, 2008 16:00:00 GMT - Timestomping

## VERIFICACIÓN PARA ESCÉPTICOS - 3 PASOS EN 2 MINUTOS

1. **Tienes Moto G04s T606?** Ejecuta: `adb shell getprop ro.build.version.security_patch`
Si dice `2026-04-06`, luego ejecuta: `adb shell getprop ro.system_ext.build.date`
Si dice `Mar 18`, tienes el "Fake Patch" activo.

2. **Busca este archivo**: `/system/etc/permissions/default-permissions-com.dti.amx.xml`
Si existe, tienes Digital Turbine con INSTALL_PACKAGES pre-concedido.

3. **Revisa tu tráfico**: `api.swishapps.ai` + `beacons.glance.inmobi.com`
Si resuelven, tu teléfono es parte de la botnet de 47M.

**No me creas. Verifica tú mismo. El teléfono no miente.**

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Direzione di ricerca

The issue describes a complex supply chain security vulnerability in Android devices, not a specific code change for the debloater tool. Research would involve understanding the reported hardcoded keys, fscrypt bypass, and specific system components like com.spreadtrum.sgps. The verification steps use ADB commands to check properties and files. 'Done' would mean the debloater can detect or mitigate these specific backdoors, but the issue does not propose a concrete patch.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
android, rust
Ambito
mobile-dev, security
Tipo di issue
Bug
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
10/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.