CVE-2024-36064: Nllcom Acr Phone

Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.

The NLL com.nll.cb (aka ACR Phone) application through 0.330-playStore-NoAccessibility-arm8 for Android allows any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.nll.cb.dialer.dialer.DialerActivity component.

Affected products

  • Nllcom Acr Phone: up to and including 0.330-playStore-NoAccessibility-arm8 for Android

Published 2024-11-07. Last modified 2026-06-17.