MuntashirAkon / android-debloat-list

[WIP] A comprehensive list of apps for debloating Android with suggestions and vulnerabilities, based on but independent of UAD project.
GNU Affero General Public License v3.0
174 stars 15 forks source link

CallEnhancement vulnerability #23

Open MuntashirAkon opened 11 months ago

MuntashirAkon commented 11 months ago

Please check before submitting an issue

Vulnerability report

CVE-2019-15472

Package name

com.qualcomm.qti.callenhancement

Package label

CallEnhancement

Affected versions

Requires investigation (see below). Reported version: 9 (28)

Removal

Remove

Additional context

As per the report, it “allows unauthorized microphone audio recording via a confused deputy attack.” No PoC is provided. So, affected versions are not known.