VYPR

CWE-926

Improper Export of Android Application Components

VariantIncomplete

Description

The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (98)

page 1 of 5
  • CVE-2026-81301HigSep 14, 2026
    risk 0.55cvss —epss 0.00

    Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps the caller-controlled URI path directly to a filesystem path and passes it to new File(...). It then…

  • CVE-2025-5344HigJul 17, 2025
    risk 0.55cvss —epss 0.00

    Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's global settings and wallpaper image. …

  • CVE-2024-13917HigMay 30, 2025
    risk 0.54cvss —epss 0.00

    An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any other malicious application, with no…

  • CVE-2025-68713HigJun 15, 2026
    risk 0.52cvss 8.0epss 0.00

    An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into the app's scoped storage. The resulting files…

  • CVE-2025-32347HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2021-25400HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.

  • CVE-2026-68928HigSep 18, 2026
    risk 0.49cvss 8.6epss 0.00

    Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins/terminal/src/android/TerminalSer…

  • CVE-2025-15464HigJan 8, 2026
    risk 0.49cvss 7.5epss 0.01

    Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.

  • CVE-2026-45528HigSep 8, 2026
    risk 0.47cvss 7.3epss 0.00

    In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2026-18994HigSep 10, 2026
    risk 0.46cvss 7.1epss 0.00

    A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application.

  • CVE-2026-21059HigAug 10, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

  • CVE-2023-41960HigOct 25, 2023
    risk 0.46cvss 7.1epss 0.00

    The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive settings of the Android Client application itself.

  • CVE-2021-25388HigJun 11, 2021
    risk 0.46cvss 7.1epss 0.00

    Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.

  • CVE-2024-13916MedMay 30, 2025
    risk 0.45cvss —epss 0.00

    An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.android.providers.settings.fingerprint.PriFpShareProvider“ content provider's…

  • CVE-2024-13915MedMay 30, 2025
    risk 0.45cvss —epss 0.00

    Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process. The application "com.pri.factorytest" (version name: 1.0, version code: 1) exposes a…

  • CVE-2021-25397MedJun 11, 2021
    risk 0.44cvss 6.8epss 0.00

    An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.

  • CVE-2026-47361MedAug 7, 2026
    risk 0.42cvss 6.4epss 0.00

    In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the activity closes and no in-process session matches that ID, it unconditionally…

  • CVE-2024-36437MedFeb 3, 2025
    risk 0.42cvss 6.5epss 0.00

    The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.…

  • CVE-2026-47363MedAug 7, 2026
    risk 0.41cvss 6.3epss 0.00

    In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it…

  • CVE-2025-5345MedJul 17, 2025
    risk 0.41cvss —epss 0.00

    Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and delete arbitrary files from device's…