CVE-2024-53936

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Jan 6, 2025
Updated: Jan 8, 2025

Summary

CVE-2024-53936 is a vulnerability affecting the com.asianmobile.callcolor, or Color Phone Call Screen App, for Android versions up to 24. This issue allows any application to place phone calls without user interaction, by exploiting a crafted intent sent to the com.asianmobile.callcolor.ui.component.call.CallActivity component. With no required permissions, an attacker could misuse this flaw to make calls surreptitiously, posing a privacy and security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share