CVE-2024-36437
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 3, 2025
Updated: Feb 5, 2025
CWE ID 926
Summary
CVE-2024-36437 is a vulnerability affecting the com.enflick.android.TextNow (TextNow: Call + Text Unlimited) application version 24.17.0.2 for Android. Maliciously crafted intents can be sent to this app's DialerActivity component, enabling any installed app (without requiring user interaction or specific permissions) to place phone calls. This vulnerability poses a significant security risk as it allows unauthorized access to the phone's call functionality.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share