Impact
The vulnerability results from Samsung Visual Voicemail incorrectly exporting Android application components, which bypasses permission checks and enables a local attacker to initiate a phone call without the required call‑making permission. This flaw is an improper permission assignment attack that can cause unauthorized calls, potentially incurring charges and exposing user contact information.
Affected Systems
The flaw affects Samsung Mobile Visual Voicemail; specific affected releases are not detailed in the CVE data, so any device running an unpatched version of the app could be vulnerable. Users should verify whether their application is up to date and consider applying vendor updates as they become available.
Risk and Exploitability
The CVSS score The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; a user or malicious app with local device access could exploit the exported component to make a call. No remote exploitation is described, so an attacker would need physical or local access to a device running the affected app.
OpenCVE Enrichment