PT-2025-30288 · Sk Telecom · Com.Skt.Prod.Dialer

Actuator

·

Published

2025-07-21

·

Updated

2025-07-21

·

CVE-2025-43977

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions com.skt.prod.dialer versions through 12.5.0
Description The application allows any installed application, without requiring any permissions, to initiate phone calls without user interaction. This is achieved by sending a specially crafted intent to the com.skt.prod.dialer.activities.outgoingcall.OutgoingCallInternalBroadcaster component.
Recommendations Update com.skt.prod.dialer to a version newer than 12.5.0.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-43977

Affected Products

Com.Skt.Prod.Dialer