Back to search
CVE-2015-3858
Published: Oct 1, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypass an intended user-confirmation requirement for SMS short-code messaging via a crafted application, aka internal bug 22314646.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[android-security-updates] 20150909 Nexus Security Bulletin (September 2015)
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now