PT-2014-8650 · Google · Android

Published

2014-12-15

·

Updated

2014-12-16

·

CVE-2014-8610

CVSS v2.0

3.3

Low

VectorAV:L/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Android versions prior to 5.0.0
Description The issue allows attackers to send stored SMS messages and transmit arbitrary new draft SMS messages, or trigger additional per-message charges from a network operator for old messages. This can be achieved via a crafted application that broadcasts an intent with the com.android.mms.transaction.MESSAGE SENT action.
Recommendations For Android versions prior to 5.0.0, consider restricting the use of the SmsReceiver receiver until a patch is available. As a temporary workaround, avoid using the com.android.mms.transaction.MESSAGE SENT action in crafted applications to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8610

Affected Products

Android