A security researcher has discovered vulnerabilities that enable 1-click MMI code execution on Android by abusing the CALL_PHONE permission in vulnerable dialer applications. The attack leverages the ability of apps to dial USSD/MMI codes silently, potentially exposing users to carrier-level operations like call forwarding or mobile banking via *99# menus.
Background
MMI and USSD codes are legacy GSM signaling protocols used for carrier services like call forwarding, balance checks, and mobile banking menus. Android's CALL_PHONE permission has long allowed apps to dial these codes, but no public exploitation chain was known until now.
- Source
- Lobsters
- Published
- Oct 10, 2026 at 03:20 PM
- Score
- 6.0 / 10