CVE-2023-47889
Binhdrm26 Super Reboot 1.0.3
Raw vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2023-47889 is a high-severity Use of Implicit Intent for Sensitive Communication (CWE-927) vulnerability in Binhdrm26 Super Reboot. Its CVSS base score is 7.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Adversary-in-the-Middle (T1557); ranked at the 20th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-4 (Information Flow Enforcement) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-51979
Vulnerability Data
The Android application BINHDRM26 com.bdrm.superreboot 1.0.3, exposes several critical actions through its exported broadcast receivers. These exposed actions can allow any app on the device to send unauthorized broadcasts, leading to unintended consequences. The vulnerability is particularly concerning because these…
more
actions include powering off, system reboot & entering recovery mode.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Enforces explicit authorization decisions on which apps may receive sensitive data, directly stopping implicit-intent broadcast.
Requires approved information-flow rules between components, which implicit intents for sensitive data violate.
Protects confidentiality of transmitted data even if an unintended receiver obtains the intent.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prohibit implicit intents for sensitive data while this single CWE addresses only one narrow coding rule.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect the weakness but does not itself prevent it at runtime.
DLP policies and technical controls directly prevent sensitive data from leaving via insecure implicit intents.
Network security rules can restrict inter-app communication channels that implicit intents rely on.
Application security requirements can mandate explicit intents or secure IPC for sensitive data.
Secure architecture principles discourage implicit intents for sensitive payloads.
Secure coding standards explicitly forbid implicit intents when handling sensitive information.