CRITICAL🇵🇱 Wersja polska

CVE-2024-53932

CVSS 9.1v3.1pub. 2025-01-06upd. 2026-04-15

The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.remi.colorphone.callscreen.calltheme.callerscreen.dialer.DialerActivity component.

🤖 AI Analysis
How it works

The component com.remi.colorphone.callscreen.calltheme.callerscreen.dialer.DialerActivity is improperly configured — it is accessible to external applications without requiring any permissions (CWE-732: improper privilege assignment; CWE-922: improper restriction of rendered UI layers or frames). An attacking application can send a crafted intent to this component, resulting in automatic initiation of a phone call without any user interaction.

Impact

An attacker (or a malicious application installed on the device) can initiate phone calls to any numbers, including premium-rate numbers, without the knowledge and consent of the device owner, which may lead to financial losses and privacy violations.

Mitigation & patch

The Color Phone: Call Screen Theme application should be updated to a version higher than 21.1.9, if the vendor has released a patch. If no patch is available, it is recommended to uninstall the application. Details are available in the vendor references and in the report at the address indicated in the CVE references.

Who is affected

The application com.remi.colorphone.callscreen.calltheme.callerscreen (Color Phone: Call Screen Theme) in version up to and including 21.1.9 on the Android platform

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References