CVE-2015-3843: Google Android
High severity, CVSS 9.3. EPSS: 1.5% chance of exploitation in the next 30 days.
The SIM Toolkit (STK) framework in Android before 5.1.1 LMY48I allows attackers to (1) intercept or (2) emulate unspecified Telephony STK SIM commands via an application that sends a crafted Intent, related to com/android/internal/telephony/cat/AppInterface.java, aka internal bug 21697171.
Affected products
- Google Android: up to and including 5.1
Published 2015-10-01. Last modified 2026-06-17.