Vulnerable Android dialer applications can be exploited to execute MMI and USSD codes with a single click. The CALL_PHONE permission allows apps to send carrier control commands to the SIM, but users are not informed of this capability and cannot decline execution. Attackers can abuse browser-reachable deeplinks in dialer apps to trigger these codes remotely without user interaction.