LiveActive security incident?Get immediate response
CVE Record

CVE-2018-15000: The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/rele...

The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.smartshot (versionCode=1, versionName=3.0.0). This app contains an exported service named com.vivo.smartshot.ui.service.ScreenRecordService that will record the screen for 60 minutes and write the mp4 file to a location of the user's choosing. Normally, a recording notification will be visible to the user, but we discovered an approach to make it mostly transparent to the user by quickly removing a notification and floating icon. The user can see a floating icon and notification appear and disappear quickly due to quickly stopping and restarting the service with different parameters that do not interfere with the ongoing screen recording. The screen recording lasts for 60 minutes and can be written directly to the attacking app's private directory.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2018-15000 is a privacy flaw in a preinstalled Vivo V7 screen recording app. A malicious app could cause screen recording for up to 60 minutes while making normal recording indicators mostly disappear. Exposure matters most where affected Vivo V7 devices handle credentials, customer data, or sensitive communications.

Executive priority

Treat this as a targeted mobile privacy risk, not a broad enterprise emergency. Prioritize if the organization uses Vivo V7 devices for privileged access, regulated data, executive communications, or customer-facing work.

Technical view

The affected Vivo V7 build includes com.vivo.smartshot version 3.0.0 with an exported ScreenRecordService. The service can record the screen and write an MP4 to a chosen location, including an attacking app's private directory. The source describes user-visible notification and floating-icon indicators being made largely transient.

Likely exposure

Exposure appears limited to Vivo V7 devices matching the cited Android 7.1.2 build fingerprint and bundled com.vivo.smartshot version. The source bundle does not identify broader Vivo models, carrier variants, or patched firmware levels.

Exploitation context

The supplied sources describe research findings from Kryptowire/DEF CON and do not show active exploitation. The CVE is not listed as KEV in the bundle. Exploitation would depend on an app being present on an affected device and invoking the vulnerable exported service.

Researcher notes

Evidence is specific but incomplete. The bundle provides no CVSS score, CWE, official patch version, or active exploitation evidence. Do not generalize beyond the named Vivo V7 build, package, version, and exported service without additional vendor or device testing.

Mitigation direction

  • Inventory fleets for the cited Vivo V7 build fingerprint.
  • Check Vivo or OEM firmware guidance for fixed builds.
  • Remove affected devices from sensitive workflows until resolved.
  • Restrict untrusted app installation on affected devices.
  • Use MDM controls to reduce third-party app exposure where possible.

Validation and detection

  • Confirm whether devices match the cited Vivo V7 fingerprint.
  • Check for com.vivo.smartshot version 3.0.0.
  • Verify whether ScreenRecordService is exported on the device.
  • Review vendor firmware notes for remediation status.
  • Look for unexpected screen-recording MP4 artifacts on affected devices.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-15000 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.