PT-2024-27670 · Mister · Mister
Edward Warren
·
Published
2024-12-04
·
Updated
2024-12-11
·
CVE-2024-37575
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Mister org.mistergroup.shouldianswer version 1.4.264
Description
The issue allows any installed application, without requiring permissions, to initiate phone calls without user interaction. This is achieved by sending a crafted intent via the
org.mistergroup.shouldianswer.ui.default dialer.DefaultDialerActivity component.Recommendations
For version 1.4.264, consider restricting access to the
org.mistergroup.shouldianswer.ui.default dialer.DefaultDialerActivity component to prevent unauthorized phone calls until a patch is available.Exploit
Fix
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mister