CVE-2024-36063: Goodwy Com Right Dialer

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activities.DialerActivity component.

Affected products

  • Goodwy Com Right Dialer: up to and including 5.1.0_for_android

Published 2024-11-07. Last modified 2026-06-17.