Executive brief
A vulnerability in the Telecom application on Samsung Note devices running Android 5.0 through 6.0 could allow an attacker to crash the phone or potentially gain elevated system privileges. This issue is triggered by the way the device handles specific call-related data, which can lead to a full system reboot or unauthorized access to sensitive functions. Exploitation typically requires a user to interact with a malicious application or file, potentially disrupting business operations or compromising device security.
Technical details
A vulnerability exists in the SpamCall Activity component of the Samsung Telecom application due to improper exception handling when processing serializable objects. An attacker can exploit this by passing a malformed serializable object to the component, leading to an application crash and subsequent device reboot (Denial of Service). Because the component may handle sensitive permissions, there is also a potential for privilege escalation. The attack vector is local, typically requiring user interaction to trigger the malicious intent. Samsung addressed this in the August 2016 security update by hardening the exception handling routines within the affected component.
Affected products
- Samsung Android (Samsung Note) 5.0, 5.1, 6.0 (Lollipop and Marshmallow)
Timeline
- 2016-05-11: disclosed: Privately reported to Samsung
- 2016-08-01: patched: Released in Samsung August 2016 Security Maintenance Release (SMR)
- 2017-01-18: advisory: NVD publication date