CVE-2014-8610 Android < 5.0 SMS resend vulnerability

Posted by Wang,Tao(Scloud) on Nov 26

INTRODUCTION
==================================
In Android <5.0, an unprivileged app can resend all the SMS stored in the user’s phone to their corresponding
recipients or senders (without user interaction).
No matter whether these SMS are sent to or received from other people. This may leads to undesired cost to user.
Even the worse, since Android also allow unprivileged app to create draft SMS, combined with this trick, bad app can…

Leave a Reply