CVE-2024-53931

CRITICAL

The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permissions) to place phone calls without user interaction by...

Affects 0 products across 2 vendors.

BCS6.12
CVSS 3.19.1
EPSS0.3%
Percentile27th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, no availability impact.
CWE Weakness Definitions
CWE-732: Incorrect Permission Assignment for Critical Resource

Software sets permissions on critical resources allowing unintended actors to read or modify them.

CWE-922: CWE-922
Related Attack Patterns (CAPEC)
CAPEC-60 Reusing Session IDs (aka Session Replay)
via CWE-732
CAPEC-61 Session Fixation
via CWE-732
CAPEC-127 Directory Indexing
via CWE-732
CAPEC-206 Signing Malicious Code
via CWE-732
CAPEC-642 Replace Binaries
via CWE-732
Show all 11

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through version 1.1 for Android is vulnerable to an intent injection attack that allows any application to place phone calls without user interaction.

BSID: BS-2025-GLOBAL-221387-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-53931?
The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through version 1.1 for Android is vulnerable to an intent injection attack that allows any application to place phone calls without user interaction.
What is the CVSS score for CVE-2024-53931?
CVE-2024-53931 has CVSS 9.1 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. EPSS: 0.3%.
Is CVE-2024-53931 actively exploited?
No confirmed active exploitation of CVE-2024-53931 as of 2026-05-30.
How do I remediate CVE-2024-53931?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-53931?
CVE-2024-53931 affects: Android, Place.
Vulnerability Details
CVE IDCVE-2024-53931
BSIDBS-2025-GLOBAL-221387-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Published2025-01-06
Last Modified2026-04-15
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.glitter.caller.screen.DialerActivity component.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can craft an intent and send it to the com.glitter.caller.screen.DialerActivity component, enabling unauthorized phone calls to be made from the device.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Android —
Place —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 564 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashd46c4e9742fb28b014359e2ba4a555278136a478c37fe6d9bf9e32a8bf22ec5bb86affde643b2e3f3a1ced98fe048f0e03ea33553a0637937b4b1a7c3eaacadd
Related CVEs affecting Android
CVE-2023-4617 10.0 Incorrect authorization vulnerability in HTTP POST method in Govee Home appli... CVE-2024-12402 9.8 The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin... CVE-2026-30496 9.8 The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0... CVE-2024-53932 9.1 The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: C... CVE-2025-69515 9.1 An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows att...
View all Android CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.1 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →