Find and Call Application for iPhone and Android contains a flaw that may lead to an unauthorized information disclosure. When downloaded, this specially crafted application will allow a remote attacker to gain access to the user's phonebook and upload it to a remote server. This will allow the server to send SMS messages containing the application URL to the numbers contained in the phonebook.
Classification
Location:
Mobile Phone / Hand-held Device
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Workaround
Exploit:
Exploit Public
Disclosure:
Third-party Disputed,
Discovered in the Wild
Solution
Currently, there are no known upgrades or patches to correct this vulnerability. It is possible to temporarily work around the flaw by implementing the following workaround: avoid downloading the find and call app. If it's downloaded, uninstall it from the device.