First published: Wed Apr 08 2020(Updated: )
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) software. The Contacts application allows attackers to originate video calls because SS (Supplementary Service) and USSD (Unstructured Supplementary Service Data) codes are improperly secured. The Samsung ID is SVE-2018-11469 (April 2018).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =6.0 | |
Google Android | =7.0 | |
Google Android | =7.1.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 | |
Google Android | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21078 is classified as a high-severity vulnerability affecting specific Samsung mobile devices.
To mitigate CVE-2018-21078, update your Samsung mobile device to the latest software version provided by Samsung.
CVE-2018-21078 affects Samsung mobile devices running Android versions 6.0, 7.x, and 8.0.
CVE-2018-21078 can allow attackers to initiate unauthorized video calls through the vulnerable Contacts application.
Currently, there is no official workaround for CVE-2018-21078 other than applying the latest security update.