CVE-2024-37573: Talkatone
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.talkatone.vedroid.ui.launcher.OutgoingCallInterceptor component.
Affected products
- Talkatone Talkatone: from 8.0.0, up to and including 8.4.6
Published 2024-10-30. Last modified 2026-06-17.