PT-2018-4106 · Google · Android
Published
2018-05-02
·
Updated
2018-06-12
·
CVE-2013-6272
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Android versions 4.1.1 through 4.4.2
Description
The issue allows attackers to bypass intended access restrictions in the NotificationBroadcastReceiver class, enabling them to make phone calls to arbitrary numbers, send mmi or ussd codes, or hang up ongoing calls via a crafted application.
Recommendations
For Android versions 4.1.1 through 4.4.2, consider restricting access to the NotificationBroadcastReceiver class until a patch is available. As a temporary workaround, avoid using the com.android.phone process for sensitive operations.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android