The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.skt.prod.dialer.activities.outgoingcall.OutgoingCallInternalBroadcaster component.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://play.google.com/store/apps/details?id=com.skt.prod.dialer | product |
https://github.com/actuator/com.skt.prod.dialer | third party advisory |
https://github.com/actuator/com.skt.prod.dialer/blob/main/CVE-2025-43977 | third party advisory |