Executive brief
InTouch Contacts & Caller ID is a mobile application used for managing, backing up, and syncing professional contact lists. A security flaw in the app's file import process allows a malicious application on the same device to overwrite the app's internal files. This could lead to the theft of sensitive contact data, app instability, or the execution of unauthorized commands on the user's device.
Technical details
A path traversal vulnerability (CWE-22) exists in the 'com.intouchapp.activities.ext_share.ExternalShareActivity' component of the InTouch Contacts & Caller ID app for Android. The vulnerability stems from insufficient validation of filenames and content during the file import process. A malicious application installed on the same device can exploit this by providing a crafted filename containing traversal sequences (e.g., ../) to overwrite sensitive files in the app's private internal storage. Successful exploitation can result in arbitrary code execution if executable files are replaced, or privilege escalation and data exposure if configuration files are modified. The attack can be triggered automatically when the victim interacts with a malicious app.
Affected products
- InTouchApp InTouch Contacts & Caller ID APP 6.38.1
Timeline
- 2026-03-31: disclosed: Vulnerability reported by Secsys-FDU at Fudan University
- 2026-03-31: advisory