CVE-2024-53934

The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes) application through 1.1.2 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.frovis.androidbase.call.DialerActivity component.
Configurations

No configuration.

History

08 Jan 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) La aplicación com.windymob.callscreen.ringtone.callcolor.colorphone (también conocida como Color Phone Call Screen Themes) hasta la versión 1.1.2 para Android permite que cualquier aplicación (sin permisos) realice llamadas telefónicas sin interacción del usuario enviando una intención manipulada a través del componente com.frovis.androidbase.call.DialerActivity.
CWE CWE-281
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.7

06 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-06 22:15

Updated : 2025-01-08 17:15


NVD link : CVE-2024-53934

Mitre link : CVE-2024-53934

CVE.ORG link : CVE-2024-53934


JSON object : View

Products Affected

No product.

CWE
CWE-281

Improper Preservation of Permissions