CVE-2024-53936
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Jan 6, 2025
Updated: Jan 8, 2025
Summary
CVE-2024-53936 is a vulnerability affecting the com.asianmobile.callcolor, or Color Phone Call Screen App, for Android versions up to 24. This issue allows any application to place phone calls without user interaction, by exploiting a crafted intent sent to the com.asianmobile.callcolor.ui.component.call.CallActivity component. With no required permissions, an attacker could misuse this flaw to make calls surreptitiously, posing a privacy and security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.