4 ms·
I think what you're asking about is security threats such as RCE, information disclosure, etc, rather than threat vectors based on social engineering. Modern m
by jamieweb 7y ago
I think what you're asking about is security threats such as RCE, information disclosure, etc, rather than threat vectors based on social engineering.
Modern mobile phones do send/receive call data in a digital format (albeit over an analogue transmission medium), so there is theoretically the potential for deserialisation vulnerabilities, buffer overflows, etc.
I'm not an expert in mobile telephony protocols, however my current understanding is that RCE/crashing a mobile device just by calling it using a standard phone line is extremely unlikely, but not impossible.
However, for desktop phone equipment (think office IP phones), the attack surface is significantly larger and there have been numerous proven attacks and against them, but these (almost always) require access to the phone via an IP network, rather than a traditional phone line.
Other 'calling' apps such as WhatsApp or Skype are a completely different question, as you've already noted.
If you're not a high-value target, I'd say that it's not a risk to be concerned about individually. Just keep your phone patched and follow other general best-practises.
In the event that a major vulnerability via phone call was discovered, it would most likely either be used in targeted attacks against high value individuals, or it'd be used in large scale 'annoyances', e.g. by teenagers pranking their friends.
As for your actual question, the repeated scam calls were most likely a broken automation system (as @lima said), or just a nasty scammer that really wanted you to answer.
As a side note, this article [1] by Google Project Zero goes into quite some detail about the fully remote/unattended attack vectors present on an iPhone. Though not directly related to your question, it's a very interesting read.
[1] https://googleprojectzero.blogspot.com/2019/08/the-fully-remote-attack-surface-of.html https://googleprojectzero.blogspot.com/2019/08/the-fully-rem...