1-click MMI execution in Android
Android applications with special permissions can execute special instructions called MMI (Man-Machine Interface) and USSD (Unstructured Supplementary Service Data) codes without the user's consent. These codes can be used to perform various actions such as forwarding calls, managing accounts, and even conducting mobile banking transactions.
The vulnerability stems from the fact that many apps with the CALL_PHONE permission can execute these codes silently, and if the app also has a browser-reachable dialing path, it can be exploited easily via a URL. This issue was discovered and reported, and it affects many popular applications. To confirm the vulnerability, a physical device was tested, and the issue was reproduced on both an emulated and a real Android device.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.