The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypass an intended user-confirmation requirement for SMS short-code messaging via a crafted application, aka internal bug 22314646.
Advisories
Source ID Title
EUVD EUVD EUVD-2015-3894 The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypass an intended user-confirmation requirement for SMS short-code messaging via a crafted application, aka internal bug 22314646.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: google_android

Published:

Updated: 2024-08-06T05:56:16.309Z

Reserved: 2015-05-12T00:00:00

Link: CVE-2015-3858

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-10-01T00:59:27.203

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-3858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses