{"api_version":"1","generated_at":"2026-07-23T10:05:21+00:00","cve":"CVE-2013-6272","urls":{"html":"https://cve.report/CVE-2013-6272","api":"https://cve.report/api/cve/CVE-2013-6272.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-6272","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-6272"},"summary":{"title":"CVE-2013-6272","description":"The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-05-02 15:29:00","updated_at":"2018-06-12 18:02:00"},"problem_types":["CWE-284"],"metrics":[],"references":[{"url":"https://curesec.com/blog/article/blog/35.html","name":"https://curesec.com/blog/article/blog/35.html","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Cureblog - Der Blog der Curesec GmbH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2014/Jul/13","name":"20140706 Conduct phonecalls on Android without the necessary permission, advisory+testapplication+exploits for testing (CVE-2013-6272 and CVE-2014-N/A)","refsource":"FULLDISC","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"Full Disclosure: Conduct phonecalls on Android without the necessary permission, advisory+testapplication+exploits for testing (CVE-2013-6272 and CVE-2014-N/A)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/127359/Android-OS-Authorization-Missing.html","name":"http://packetstormsecurity.com/files/127359/Android-OS-Authorization-Missing.html","refsource":"MISC","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Android OS Authorization Missing ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/68415","name":"68415","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Google Android CVE-2013-6272 Remote Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/94423","name":"google-android-cve20136272-sec-bypass(94423)","refsource":"XF","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-6272","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-6272","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"6272","vulnerable":"1","versionEndIncluding":"4.4.2","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2013-6272","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20140706 Conduct phonecalls on Android without the necessary permission, advisory+testapplication+exploits for testing (CVE-2013-6272 and CVE-2014-N/A)","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2014/Jul/13"},{"name":"google-android-cve20136272-sec-bypass(94423)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/94423"},{"name":"http://packetstormsecurity.com/files/127359/Android-OS-Authorization-Missing.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/127359/Android-OS-Authorization-Missing.html"},{"name":"https://curesec.com/blog/article/blog/35.html","refsource":"MISC","url":"https://curesec.com/blog/article/blog/35.html"},{"name":"68415","refsource":"BID","url":"http://www.securityfocus.com/bid/68415"}]}},"nvd":{"publishedDate":"2018-05-02 15:29:00","lastModifiedDate":"2018-06-12 18:02:00","problem_types":["CWE-284"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:google:android:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1.1","versionEndIncluding":"4.4.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"6272","Ordinal":"65979","Title":"CVE-2013-6272","CVE":"CVE-2013-6272","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"6272","Ordinal":"1","NoteData":"The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application.","Type":"Description","Title":null},{"CveYear":"2013","CveId":"6272","Ordinal":"2","NoteData":"2018-05-02","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"6272","Ordinal":"3","NoteData":"2018-05-02","Type":"Other","Title":"Modified"}]}}}