CWE-926
Improper Export of Android Application Components
Description
The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (98)
page 2 of 5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-21063 | Med | 0.40 | 6.1 | 0.00 | Aug 10, 2026 | Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. | ||
| CVE-2026-20470 | Med | 0.40 | 6.2 | 0.00 | Aug 3, 2026 | In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189. | ||
| CVE-2026-12960 | Med | 0.39 | — | 0.00 | Jul 3, 2026 | An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Security Update for ASUS Router Android App '… | ||
| CVE-2026-54318 | Hig | 0.39 | 7.1 | 0.00 | Jun 23, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play… | ||
| CVE-2026-21113 | Med | 0.36 | 5.5 | 0.00 | Sep 9, 2026 | Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission. | ||
| CVE-2026-21108 | Med | 0.36 | 5.5 | 0.00 | Sep 9, 2026 | Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information. | ||
| CVE-2026-20516 | Med | 0.36 | 5.5 | 0.00 | Sep 7, 2026 | In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882. | ||
| CVE-2026-44965 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2026 | In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, DashboardWidgetActivity) are exported… | ||
| CVE-2026-44279 | Med | 0.36 | 5.5 | 0.00 | May 12, 2026 | An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to disclose information via an exported Content Provider URI. | ||
| CVE-2026-3291 | Med | 0.36 | 5.5 | 0.00 | May 6, 2026 | Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities. | ||
| CVE-2025-20934 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege. | ||
| CVE-2023-20962 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction… | ||
| CVE-2025-27599 | Med | 0.35 | 6.5 | 0.00 | Apr 18, 2025 | Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a webpage with similar permissions to Element Call and… | ||
| CVE-2026-18604 | Med | 0.34 | 5.3 | 0.00 | Aug 3, 2026 | A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be… | ||
| CVE-2025-14517 | Med | 0.34 | 5.3 | 0.00 | Dec 11, 2025 | A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity of the file AndroidManifest.xml. Executing manipulation can lead to improper export of android application components. The attack can only be executed locally. The exploit has been… | ||
| CVE-2025-10722 | Med | 0.34 | 5.3 | 0.00 | Sep 19, 2025 | A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android. This affects an unknown function of the file AndroidManifest.xml of the component com.dw.android.mukbee. The manipulation results in improper export of android application components. The attack must be… | ||
| CVE-2025-10721 | Med | 0.34 | 5.3 | 0.00 | Sep 19, 2025 | A vulnerability was determined in Webull Investing & Trading App 11.2.5.63 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml. This manipulation causes improper export of android application components. The attack can only be executed locally.… | ||
| CVE-2025-10718 | Med | 0.34 | 5.3 | 0.00 | Sep 19, 2025 | A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android. This affects an unknown part of the component com.ooma.office2. The manipulation results in improper export of android application components. The attack needs to be approached locally. The… | ||
| CVE-2025-10717 | Med | 0.34 | 5.3 | 0.00 | Sep 19, 2025 | A vulnerability has been found in intsig CamScanner App 6.91.1.5.250711 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.intsig.camscanner. The manipulation leads to improper export of android application… | ||
| CVE-2025-10716 | Med | 0.34 | 5.3 | 0.00 | Sep 19, 2025 | A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.cxsw.sdprinter. Executing manipulation can lead to improper export of android application… |
- risk 0.40cvss 6.1epss 0.00
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.
- risk 0.40cvss 6.2epss 0.00
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189.
- risk 0.39cvss —epss 0.00
An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Security Update for ASUS Router Android App '…
- risk 0.39cvss 7.1epss 0.00
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play…
- risk 0.36cvss 5.5epss 0.00
Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.
- risk 0.36cvss 5.5epss 0.00
Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.
- risk 0.36cvss 5.5epss 0.00
In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.
- risk 0.36cvss 5.5epss 0.00
In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, DashboardWidgetActivity) are exported…
- risk 0.36cvss 5.5epss 0.00
An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to disclose information via an exported Content Provider URI.
- risk 0.36cvss 5.5epss 0.00
Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.
- risk 0.36cvss 5.5epss 0.00
In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction…
- risk 0.35cvss 6.5epss 0.00
Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a webpage with similar permissions to Element Call and…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application components. The attack needs to be…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity of the file AndroidManifest.xml. Executing manipulation can lead to improper export of android application components. The attack can only be executed locally. The exploit has been…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android. This affects an unknown function of the file AndroidManifest.xml of the component com.dw.android.mukbee. The manipulation results in improper export of android application components. The attack must be…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was determined in Webull Investing & Trading App 11.2.5.63 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml. This manipulation causes improper export of android application components. The attack can only be executed locally.…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android. This affects an unknown part of the component com.ooma.office2. The manipulation results in improper export of android application components. The attack needs to be approached locally. The…
- risk 0.34cvss 5.3epss 0.00
A vulnerability has been found in intsig CamScanner App 6.91.1.5.250711 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.intsig.camscanner. The manipulation leads to improper export of android application…
- risk 0.34cvss 5.3epss 0.00
A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.cxsw.sdprinter. Executing manipulation can lead to improper export of android application…