Files
cve/2013/CVE-2013-6272.md

19 lines
859 B
Markdown
Raw Permalink Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2013-6272](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6272)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
2025-09-29 21:09:30 +02:00
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
2024-05-26 14:27:05 +02:00
### Description
The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application.
### POC
#### Reference
- http://packetstormsecurity.com/files/127359/Android-OS-Authorization-Missing.html
- http://seclists.org/fulldisclosure/2014/Jul/13
#### Github
No PoCs found on GitHub currently.