CVE-2024-36063
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-36063 is a vulnerability affecting the com.goodwy.dialer, or Right Dialer, application for Android versions up to 5.1.0. The issue allows any application, regardless of permissions, to place phone calls silently by sending a specially crafted intent to the com.goodwy.dialer.activities.DialerActivity component. This vulnerability poses a significant risk to user privacy and security, as unauthorized phone calls can lead to financial loss, identity theft, and unintended communication. Users are advised to update their Right Dialer application as soon as a patch becomes available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.