{
  "id": 13363575,
  "title": "1-click MMI execution in Android",
  "url": "https://urgent.news/2026/10/10/1-click-mmi-execution-in-android",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-10T07:20:53.000Z",
  "source": {
    "name": "Lobsters",
    "slug": "lobsters",
    "url": "https://karansaini.com/mmi-android/"
  },
  "original_language": "en",
  "account": "Android applications with special permissions can execute special instructions called MMI (Man-Machine Interface) and USSD (Unstructured Supplementary Service Data) codes without the user's consent. These codes can be used to perform various actions such as forwarding calls, managing accounts, and even conducting mobile banking transactions. The vulnerability stems from the fact that many apps with the CALL_PHONE permission can execute these codes silently, and if the app also has a browser-reachable dialing path, it can be exploited easily via a URL. This issue was discovered and reported, and it affects many popular applications. To confirm the vulnerability, a physical device was tested, and the issue was reproduced on both an emulated and a real Android device.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}