This article describes how vulnerable dialer applications can be exploited to achieve 1-click MMI execution in Android.

Introduction

I’ve known for some time that Android apps with the CALL_PHONE permission can dial USSD and MMI codes alongside regular phone numbers. For as long as I have known this, I have wanted to develop an attack to execute MMI codes from an application or a web page with little or no user interaction. Three years ago, I created a proof of concept that would silently forward calls on a handset by abusing the CALL_PHONE permission. This would have obviously required a user to sideload the malicious application, undermining its impact. Last month, I discovered and reported vulnerabilities resulting in 1-click MMI execution where a user has a vulnerable dialer application installed on their device.