PT-2024-26875 · Unknown · Com.Goodwy.Dialer

Edward Warren

·

Published

2024-11-07

·

Updated

2024-11-08

·

CVE-2024-36063

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions com.goodwy.dialer (aka Right Dialer) versions through 5.1.0
Description The issue allows any application to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activities.DialerActivity component. This enables unauthenticated phone call execution.
Recommendations For versions through 5.1.0, consider disabling the com.goodwy.dialer.activities.DialerActivity component to prevent unauthorized phone calls until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-36063

Affected Products

Com.Goodwy.Dialer