Urgent.News

What's breaking now, across thousands of outlets.

Tech

1-click MMI execution in Android

Android applications with special permissions can execute special instructions called MMI (Man-Machine Interface) and USSD (Unstructured Supplementary Service Data) codes without the user's consent. These codes can be used to perform various actions such as forwarding calls, managing accounts, and even conducting mobile banking transactions.

The vulnerability stems from the fact that many apps with the CALL_PHONE permission can execute these codes silently, and if the app also has a browser-reachable dialing path, it can be exploited easily via a URL. This issue was discovered and reported, and it affects many popular applications. To confirm the vulnerability, a physical device was tested, and the issue was reproduced on both an emulated and a real Android device.

Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at karansaini.com →

More in Tech

Telegram Channels Are Order Books: Volume Spikes Precede Price Moves

A Telegram channel is not a media feed. It is a market. The proof: the posts have prices in them, and the price lines have shape.

  • Telegram channels function like order books with price information
  • Volume spikes often precede market price changes
  • Bot-farmed channels may indicate spoofing, identifiable by five checks

More from Saturday 10 October →