A vulnerability in Verizon's Call Filter feature allowed customers to access incoming call logs for another Verizon Wireless number.

The vulnerability was discovered in February by security researcher Evan Connelly and was patched by Verizon sometime in March. However, we don't know the exact length of time the Call Filter vulnerability existed.
Verizon's Call Filter app is a free utility that allows users to detect unwanted calls and automatically block them. The paid (Plus) version offers more features, including a spam lookup tool and a risk meter. It's also possible to apply blocks by caller type and get caller ID for unknown numbers.
See also: Chrome 135 and Firefox 137 fix high-severity vulnerabilities
The free version of the app is pre-installed and enabled by default on eligible Android and iOS devices purchased directly from Verizon.
Researcher Connelly reportedly only tested Call Filter for iOSwhen he discovered the bug. However, he noted that the Android app may also be affected, as the issue was found in the feature's API, so it's not related to the apps themselves.
Call history disclosure
While using Call Filter, the researcher discovered that the application was connecting to an API endpoint, https://clr-aqx.cequintvzwecid.com/clr/callLogRetrieval, to retrieve the incoming call history and display it in the application.
“This endpoint requires a JWT (JSON Web Token) in the Authorization header using the Bearer scheme and uses an X-Ceq-MDN header to specify a mobile phone number for retrieving call history logs,” explains Connelly.
“A JWT has three parts: header, payload, and signature. It is often used for authentication and authorization in web apps.“.
See also: Hackers exploit critical vulnerability in CrushFTP
According to Connelly, the payload includes various data, including the phone number of the logged-in user making the API request.
However, the researcher discovered that the phone number in the JWT payload for the logged-in user was not verified against the phone number from which the incoming call logs were requested. This means that any user could send requests using their own JWT token, but could replace the X-Ceq-MDN header with another Verizon phone to retrieve the incoming call history.

“Call metadata may seem harmless, but in the wrong hands, it becomes a powerful surveillance tool. With unrestricted access to another user’s call history, an attacker could reconstruct daily routines, identify frequent contacts, and more,” Connelly explained.
The researcher praised Verizon for its prompt response to the disclosure of the Call Filter vulnerability, but stressed that the company has followed worrying practices in handling subscribers' call data
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Critical vulnerability discovered in Canon printer drivers
The vulnerable API endpoint used by Call Filter appears to be hosted on a server owned by a separate telecommunications technology company called Cequin, which specializes in caller ID. Cequint's website was offline and public information about it is limited, raising concerns about how Verizon handles sensitive call data.
Summary: Risks & Impacts
- Privacy Violation: Anyone could see who a user was calling.
- Social engineering:Incomingcalls include information that could be exploited for fraud or phishing.
- Legal implications: Verizon could face penalties for a data breach.
This vulnerability shows how important security is in APIs, especially in telecommunications companies where data leakage can have huge consequences.
Source: www.bleepingcomputer.com
