CVE-2024-36063

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 7, 2024
Updated: Nov 8, 2024
CWE ID 276

Summary

CVE-2024-36063 is a vulnerability affecting the com.goodwy.dialer, or Right Dialer, application for Android versions up to 5.1.0. The issue allows any application, regardless of permissions, to place phone calls silently by sending a specially crafted intent to the com.goodwy.dialer.activities.DialerActivity component. This vulnerability poses a significant risk to user privacy and security, as unauthorized phone calls can lead to financial loss, identity theft, and unintended communication. Users are advised to update their Right Dialer application as soon as a patch becomes available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share