Intel

AIKIDO-2025-10168

flutter_callkit_incoming is vulnerable to Improper Access Control

Improper Access Control Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 19, 2025

65

Medium Risk

This Affects:

DARTflutter_callkit_incoming
1.0.0 - 2.5.0
Fixed in 2.5.1
Are you affected? Scan for Free

TL;DR

Affected versions of the flutter_callkit_incoming package are vulnerable to Task Hijacking due to misconfigurations in AndroidManifest.xml related to Task Control features. This vulnerability allows unauthorized attackers or malware to take over legitimate apps, potentially leading to the theft of sensitive user information.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

flutter_callkit_incoming is vulnerable to Improper Access Control in versions 1.0.0 - 2.5.0.

How to fix this

Upgrade the flutter_callkit_incoming library to the patch version.