Mobile apps could be abused to make expensive phone calls
A security precaution skipped in mobile applications such as Facebook's Messenger could be abused to make an expensive phone call at a victim's expense, a developer contends. — Phone numbers often appear as links on a mobile device.
Context & Ripple Effects
Mobile security coverage had already tied handset features to financial and social-engineering risk, from costly Windows Mobile malware to iPhone phishing warnings. The allegation shifts attention to a mundane interaction point: an app handing a phone-number link to the device dialer.
Facebook had also drawn scrutiny over Messenger’s Android permissions while expanding its mobile-linking efforts. That makes validation of actions triggered from app content—not merely the permissions an app requests—a relevant security boundary.
First-order effects
- Messenger and other affected app teams face pressure to review how phone-number links are parsed and whether costly calls can be initiated without a clear user confirmation.
- Users of apps that omit the cited precaution may be exposed to unexpected calling charges when a malicious or misleading link is opened.
Second-order effects
- Facebook’s existing defense of Messenger permissions as an Android-policy issue becomes less sufficient if concern moves from requested access to how the app invokes phone functions.
- Developers building mobile link-routing features will need to treat dialer handoffs as security-sensitive flows, alongside anti-phishing protections highlighted in earlier iPhone research.
Third-order effects
- As mobile apps increasingly connect content to device-level actions, platform and app developers will be pushed toward explicit confirmation and stronger validation at those handoff points rather than relying on permission screens alone.
The trend: Mobile-security risk is shifting from standalone malware toward unsafe handoffs between app content and privileged device functions.