CVE-2015-3840
MEDIUMAndroid < 5.1.1 - Unauthenticated SMS/MMS Status Manipulation via MessageStatusReceiver
Title source: llmDescription
The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.
References (3)
Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
http://blog.trendmicro.com/trendlabs-security-intelligence/two-new-android-bugs-mess-up-messaging-may-lead-to-multiple-send-charges/
Third Party Advisory x_refsource_confirm
http://blog.trendmicro.com/trendlabs-security-intelligence/os-x-zero-days-on-the-rise-a-2015-midyear-review-on-advanced-attack-surfaces/
Broken Link x_refsource_confirm
https://huntcve.github.io/2017/02/13/cveupdate/
Scores
CVSS v3
5.5
EPSS
0.0019
EPSS Percentile
9.4%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-284
Status
published
Products (1)
google/android
< 5.1.1
Published
Jun 27, 2017
Tracked Since
Feb 18, 2026