First published: Wed May 02 2018(Updated: )
The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android | >=4.1.1<=4.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2013-6272 vulnerability is classified as a high severity issue due to its potential to allow unauthorized phone calls and access to sensitive telephony functions.
To mitigate CVE-2013-6272, it is recommended to update the Android device to a version higher than 4.4.2 where the vulnerability is patched.
CVE-2013-6272 affects Google Android versions 4.1.1 to 4.4.2.
CVE-2013-6272 allows attackers to bypass access restrictions, resulting in the ability to make calls, send codes, or intercept ongoing calls.
Exploitation of CVE-2013-6272 can occur through untrusted applications aimed at manipulating telephony functions on vulnerable Android devices.