Glitter Caller Screen Insecure Permission Vulnerability Allowing Unauthorized Phone Calls

Vulnerability

A vulnerability in the Glitter Caller Screen application (also known as iCaller, Caller Theme & Dialer) for Android, in versions through 1.1, allows any application to make phone calls on behalf of the user without permission or interaction. This is achieved by sending a specially crafted intent to the exported 'com.glitter.caller.screen.DialerActivity' component.

Impact

Exploitation of this vulnerability enables unauthorized phone calls to be placed from the user's device, without their knowledge or consent.

Reproduction

The vulnerability can be reproduced by sending a crafted intent to the 'com.glitter.caller.screen.DialerActivity' component from a malicious third-party application installed on the device. This intent must be designed to exploit the insecure permission handling of the Glitter Caller Screen app, taking advantage of the fact that the 'DialerActivity' is exported and accessible to other applications.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.0
remediation
0.0
relevance
0.0
threat
1.6
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.