1-click MMI execution in Android
Summary
A security researcher reveals that the Android CALL_PHONE permission can be abused to silently execute MMI/USSD codes and perform call forwarding through vulnerable dialer apps. The article walk-throughs demonstrate a 1-click MMI execution via a web page and Chrome intents, discuss Android 17 changes, and provide a disclosure timeline.