CVE-2023-38301
About
An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers. Various software builds for the BLU View 2, Boost Mobile Celero 5G, Sharp Rouvo V, Motorola Moto G Pure, Motorola Moto G Power, T-Mobile Revvl 6 Pro 5G, and T-Mobile Revvl V+ 5G devices leak the device serial number to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in these instances they are leaked by a high-privilege process and can be obtained indirectly. The software build fingerprints for each confirmed vulnerable device are as follows: BLU View 2 (BLU/B131DL/B130DL:11/RP1A.200720.011/1672046950:user/release-keys); Boost Mobile Celero 5G (Celero5G/Jupiter/Jupiter:11/RP1A.200720.011/SW_S98119AA1_V067:user/release-keys); Sharp Rouvo V (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:user/release-keys); Motorola Moto G Pure (motorola/ellis_trac/ellis:11/RRHS31.Q3-46-110-2/74844:user/release-keys, motorola/ellis_trac/ellis:11/RRHS31.Q3-46-110-7/5cde8:user/release-keys, motorola/ellis_trac/ellis:11/RRHS31.Q3-46-110-10/d67faa:user/release-keys, motorola/ellis_trac/ellis:11/RRHS31.Q3-46-110-13/b4a29:user/release-keys, motorola/ellis_trac/ellis:12/S3RH32.20-42-10/1c2540:user/release-keys, motorola/ellis_trac/ellis:12/S3RHS32.20-42-13-2-1/6368dd:user/release-keys, motorola/ellis_a/ellis:11/RRH31.Q3-46-50-2/20fec:user/release-keys, motorola/ellis_vzw/ellis:11/RRH31.Q3-46-138/103bd:user/release-keys, motorola/ellis_vzw/ellis:11/RRHS31.Q3-46-138-2/e5502:user/release-keys, and motorola/ellis_vzw/ellis:12/S3RHS32.20-42-10-14-2/5e0b0:user/release-keys); Motorola Moto G Power (motorola/tonga_g/tonga:11/RRQ31.Q3-68-16-2/e5877:user/release-keys and motorola/tonga_g/tonga:12/S3RQS32.20-42-10-6/f876d3:user/release-keys); T-Mobile Revvl 6 Pro 5G (T-Mobile/Augusta/Augusta:12/SP1A.210812.016/SW_S98121AA1_V070:user/release-keys); and T-Mobile Revvl V+ 5G (T-Mobile/Sprout/Sprout:11/RP1A.200720.011/SW_S98115AA1_V077:user/release-keys). This malicious app reads from the "vendor.gsm.serial" system property to indirectly obtain the device serial number.
Rainforest analyst review
This is a privacy leak with a narrow blast radius. On the listed devices — the BLU View 2, Boost Celero 5G, Sharp Rouvo V, several Motorola Moto G models, and the T-Mobile Revvl 6 Pro and Revvl V+ — a high-privilege system process copies the non-resettable device serial number into the vendor.gsm.serial system property, where any local app can read it with no permissions at all. Android 10 deliberately blocked apps from reading such identifiers; this hands the same value back through a side door.
The reason to keep this in perspective is written into the vector: it's local, low-impact, and only exposes confidentiality. Someone needs to already have gotten a malicious or over-curious app onto the device to abuse it, and the payoff is a stable hardware identifier useful for tracking and fingerprinting — a real privacy harm, but not a compromise, not remote, and not a path to control of the device.
We rank this well down and handle it as a mobile-fleet inventory question rather than an incident. The practical action is checking whether any of these specific device builds appear in a managed fleet and leaning on app-vetting to keep untrusted apps off them; the leak only matters once an adversarial app is present. For most estates this is a note in the asset record, not a patch scramble.
References
Related CVEs
Frequently asked questions
What is CVE-2023-38301?
An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers.
How severe is CVE-2023-38301?
CVE-2023-38301 carries a CVSS 3.1 base score of 3.4, rated low. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 33 out of 100, in the moderate band.
How is CVE-2023-38301 exploited?
According to the CVSS vector (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N): attack vector Local, attack complexity Low, privileges required High, user interaction None. Impact on confidentiality Low, integrity Low and availability None.
How do I fix CVE-2023-38301?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
