CVE-2025-43977
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.skt.prod.dialer.activities.outgoingcall.OutgoingCallInternalBroadcaster component.
Affected (1)
Products: Sktelecom: Com.skt.prod.dialer
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.5.0 |
References (3)
Source: cve@mitre.org
Third Party Advisory
Timeline
No history available yet.