CVE-2024-36437

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 3, 2025
Updated: Feb 5, 2025
CWE ID 926

Summary

CVE-2024-36437 is a vulnerability affecting the com.enflick.android.TextNow (TextNow: Call + Text Unlimited) application version 24.17.0.2 for Android. Maliciously crafted intents can be sent to this app's DialerActivity component, enabling any installed app (without requiring user interaction or specific permissions) to place phone calls. This vulnerability poses a significant security risk as it allows unauthorized access to the phone's call functionality.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share