Security readout for executives and security teams
Plain-English summary
This flaw lets any app already installed on certain Coolpad-manufactured Android phones trigger a factory reset without special permissions. The main business risk is data loss and device disruption, not remote system takeover. Evidence in the source bundle names specific older devices and does not show active exploitation.
Executive priority
Treat this as a managed-fleet hygiene issue with real data-loss impact. Prioritize if affected devices hold business data, lack reliable backups, or allow unmanaged app installation. It is less urgent than remotely exploitable mobile vulnerabilities based on the provided evidence.
Technical view
CVE-2018-15003 concerns an exported broadcast receiver, com.qualcomm.qti.telephony.extcarrierpack.UiccReceiver, in the preinstalled platform app com.qualcomm.qti.telephony.extcarrierpack version 7.1.1. On named Coolpad Defiant and T-Mobile Revvl Plus builds, any co-located app can invoke factory reset behavior without permissions, causing user data and installed apps to be removed.
Likely exposure
Exposure appears limited to the Coolpad Defiant cp3632a Android 7.1.1 build and T-Mobile Revvl Plus alchemy Android 7.1.1 build named in the CVE. Organizations are mainly exposed if these legacy devices remain in use, especially where users can install untrusted apps.
Exploitation context
The source bundle does not cite KEV listing or active exploitation. Abuse requires an app already present on the device. The issue bypasses normal Android restrictions because the vulnerable capability is exposed through a preinstalled platform app component.
Researcher notes
The public record is specific about vulnerable components and device builds, but the bundle provides no CVSS score, CWE, patch identifier, or exploitation evidence. Avoid generalizing to all Qualcomm, Coolpad, or Android 7.1.1 devices without additional source support.
Mitigation direction
- Inventory fleets for the named Coolpad Defiant and T-Mobile Revvl Plus builds.
- Check vendor, carrier, or firmware guidance for an official fix or update.
- Retire or isolate affected legacy devices if no supported update exists.
- Restrict installation of untrusted apps through MDM or enterprise policy.
- Ensure user data is backed up or synced off-device.
Validation and detection
- Confirm device model, Android build, and firmware against the CVE description.
- Check whether com.qualcomm.qti.telephony.extcarrierpack versionCode 25 is installed.
- Review the app manifest for the exported UiccReceiver component and permission protection.
- Verify whether vendor or carrier firmware updates remove or protect the receiver.
- Document any affected assets and compensating controls in device inventory.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-15003 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.kryptowire.com/portal/wp-content/uploads/2018/12/DEFCON-26-Johnson-and-Stavrou-Vulnerable-Out-of-the-Box-An-Eval-of-Android-Carrier-Devices-WP-Updated.pdfCVE reference · x_refsource_MISC
- https://www.kryptowire.com/portal/android-firmware-defcon-2018/CVE reference · x_refsource_MISC
- https://www.kryptowire.com/CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
