# CVE-2024-10576

## Summary

- **CVE ID:** CVE-2024-10576
- **Severity:** CRITICAL
- **CVSS Score:** 9.4 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/R:I/V:D/U:Amber)
- **CWE:** CWE-925
- **Published:** Dec 4, 2024
- **Last Modified:** Mar 13, 2026

## Description

Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perform a factory reset without any Android system permissions. 

After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.

## Affected Products

- Infinix Mobile — com.transsion.agingfunction (13)

## References

- [CNA](https://cert.pl/en/posts/2024/12/CVE-2024-10576/)
- [CNA](https://cert.pl/posts/2024/12/CVE-2024-10576/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._