CVE-2024-36064

CVSS 3.1 Score 6.2 of 10 (medium)

Details

Published Nov 7, 2024
Updated: Nov 8, 2024
CWE ID 79

Summary

CVE-2024-36064 is a vulnerability affecting the NLL com.nll.cb (ACR Phone) application for Android. This issue permits any installed app, without requiring specific permissions, to place phone calls silently by sending a crafted intent to the com.nll.cb.dialer.dialer.DialerActivity component. This vulnerability poses a significant risk to user privacy and security as unauthorized calls can be made without user interaction. Malicious apps can exploit this weakness to carry out unwanted calls or even conduct phishing scams, among other nefarious activities. Users are advised to update their NLL com.nll.cb app to the latest version or consider using alternative, more secure communication methods.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share