CVE-2024-53934
CVSS 3.1 Score 7.7 of 10 (high)
Details
Published Jan 6, 2025
Updated: Jan 8, 2025
CWE ID 281
Summary
CVE-2024-53934 is a vulnerability affecting the com.windymob.callscreen.ringtone.callcolor.colorphone app, also known as Color Phone Call Screen Themes, on Android. This issue permits any application, without requiring user-granted permissions, to initiate phone calls quietly through a crafted intent. The vulnerability lies within the com.frovis.androidbase.call.DialerActivity component. Exploitation of this flaw could potentially lead to unauthorized phone calls, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.