Executive brief
Samsung Visual Voicemail is a mobile application that manages voicemail messages on Android devices. A flaw in how the app exports internal components allows a malicious local app on the same device to initiate calls without authorization, potentially leading to unwanted call charges or fraudulent activity.
Technical details
The vulnerability is an improper export of Android application components in Samsung Visual Voicemail versions prior to 20.1.00.05. The flaw allows the app's internal broadcast receivers, services, or other components to be invoked by other unprivileged applications on the device without proper permission checks. An attacker with a local malicious app can exploit this to trigger call initiation functionality that should be restricted to the Visual Voicemail app itself. This is a local attack requiring the attacker to have an app installed on the target device, but no specific user interaction is needed beyond app installation. Samsung has patched this vulnerability in version 20.1.00.05 and later.
Affected products
- Samsung Visual Voicemail prior to 20.1.00.05
Timeline
- 2026-09-09: disclosed