The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2014/Jul/13 | mailing list exploit third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/94423 | vdb entry third party advisory |
http://packetstormsecurity.com/files/127359/Android-OS-Authorization-Missing.html | exploit vdb entry third party advisory |
https://curesec.com/blog/article/blog/35.html | third party advisory exploit |
http://www.securityfocus.com/bid/68415 | vdb entry third party advisory |