CVE-2024-53936

MEDIUM

Color Phone Call Screen App <24 - RCE

Title source: llm
STIX 2.1

Description

The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.asianmobile.callcolor.ui.component.call.CallActivity component.

Scores

CVSS v3 6.3
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Published Jan 06, 2025
Tracked Since Feb 18, 2026