PT-2023-28358 · Unknown · Com.Cutestudio.Colordialer

·

CVE-2023-42468

·

Publicado

2023-09-13

·

Atualizado

2024-09-26

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions com.cutestudio.colordialer versions 2.1.8-2 and earlier
Description The issue allows a remote attacker to initiate phone calls without user consent due to improper export of the com.cutestudio.dialer.activities.DialerActivity component. A third-party application can craft an intent targeting com.cutestudio.dialer.activities.DialerActivity via the android.intent.action.CALL action in conjunction with a tel: URI, thereby placing a phone call.
Recommendations For versions 2.1.8-2 and earlier, consider disabling the com.cutestudio.dialer.activities.DialerActivity component until a patch is available to prevent unauthorized phone calls. Restrict access to the android.intent.action.CALL action to minimize the risk of exploitation. Avoid using the tel: URI scheme in conjunction with the com.cutestudio.dialer.activities.DialerActivity component until the issue is resolved.

Exploit

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-42468

Produtos afetados

Com.Cutestudio.Colordialer