CVE-2024-36064
CVSS 3.1 Score 6.2 of 10 (medium)
Details
Summary
CVE-2024-36064 is a vulnerability affecting the NLL com.nll.cb (ACR Phone) application for Android. This issue permits any installed app, without requiring specific permissions, to place phone calls silently by sending a crafted intent to the com.nll.cb.dialer.dialer.DialerActivity component. This vulnerability poses a significant risk to user privacy and security as unauthorized calls can be made without user interaction. Malicious apps can exploit this weakness to carry out unwanted calls or even conduct phishing scams, among other nefarious activities. Users are advised to update their NLL com.nll.cb app to the latest version or consider using alternative, more secure communication methods.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.