Actually the browser somewhat does matter.

When testing with chrome, an iframe that contains a "tel:" address which
can trigger a phone call does not get parsed automatically. You must click
on a link which has this as a target, which is the expected/anticipated use
case.

Also, part of the issue as outlined at ekoparty is that the customized
Samsung dialer, not the stock android one, automatically dials these tel:
intents that it receives.

Thus makings a stock browser, which will automatically parse an iframe tel:
link, combined with an unpatched Samsung dialer result in an unsafe state.

>From what I've gathered from some tests and what other people are reporting
is Samsung has rolled out a fix, and it appears to be trickling out to
carriers at this time. Unlocked/non-carrier devices and AT&T devices, I can
confirm are patched/updatable.
On Sep 25, 2012 3:34 PM, "Sebastian Perez" <[email protected]> wrote:

> Hi Alexey,
>
> Does not matter what browser do you have, the vulnerability does not
> exploit browser's vulnerabilities. This is an Android vulnerability that
> execute USSD codes that can be loaded from a webpage.
>
> Seba
>
> "0 be 1 can not be"
> "El verdadero hombre inteligente es el que aparenta ser pelotudo delante
> de un pelotudo que aparenta ser inteligente"
>
>
>
> On Tue, Sep 25, 2012 at 4:24 PM, Alexey Eromenko <[email protected]> wrote:
>
>> Are all web browsers affected?
>> Or only Android browser? How about Chrome or Firefox?
>>
>> --
>> You received this message because you are subscribed to the Google Groups
>> "Android Security Discussions" group.
>> To post to this group, send email to
>> [email protected].
>> To unsubscribe from this group, send email to
>> [email protected].
>> For more options, visit this group at
>> http://groups.google.com/group/android-security-discuss?hl=en.
>>
>
>  --
> You received this message because you are subscribed to the Google Groups
> "Android Security Discussions" group.
> To post to this group, send email to
> [email protected].
> To unsubscribe from this group, send email to
> [email protected].
> For more options, visit this group at
> http://groups.google.com/group/android-security-discuss?hl=en.
>

-- 
You received this message because you are subscribed to the Google Groups 
"Android Security Discussions" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/android-security-discuss?hl=en.

Reply via email to