Skip to content
Android Dialer Vulnerability Enables One-Tap Call Forwarding Hijack

Android Dialer Vulnerability Enables One-Tap Call Forwarding Hijack

First seen 10 Oct 2026, 18:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 10, 2026 at 19:35 UTC
  • •Vulnerability allows one-tap call forwarding hijack via MMI codes.
  • •66 of 88 scanned apps with CALL_PHONE permission are affected.
  • •Google classifies the issue as a third-party app problem.

A security researcher has demonstrated a vulnerability in Android dialer apps that allows attackers to silently execute MMI codes via a single tap on a web link. This exploit targets apps with the CALL_PHONE permission, enabling unauthorized call forwarding without user consent. The researcher, known as karansaini, found that 66 out of 88 scanned call and VoIP applications declared the CALL_PHONE permission, with 54 exposing browser-reachable dialer deeplinks. The exploit was confirmed on devices running Android 16 and an emulator for Android 17. Google has classified this issue as a third-party app problem rather than an OS vulnerability. The researcher reported that the attack could intercept important calls, including one-time passcodes and bank verification callbacks. The vulnerability poses significant risks to users with vulnerable dialer applications installed on their devices.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-11-07
CVE-2024-36064 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-10
Vulnerability demonstration published
A security researcher demonstrated a one-tap call forwarding exploit affecting Android dialer apps with CALL_PHONE permission.
News.Lavx.Hu
2026-10-10
Researcher reports vulnerability
The researcher, karansaini, detailed the exploit and its implications on their personal website.
karansaini.com

More articles in this cluster (2)

Following this threat?

Track CVE-2024-36064 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which Android versions are affected?
The vulnerability affects Android devices with dialer applications that have the CALL_PHONE permission, confirmed on Android 16 and an emulator for Android 17.
How can this vulnerability be exploited?
Attackers can exploit this vulnerability by crafting a web link that triggers the dialer to execute MMI codes, allowing unauthorized call forwarding.
What should users do to protect themselves?
Users should avoid installing untrusted dialer applications and monitor their call forwarding settings regularly.