CWE-926
Improper Export of Android Application Components
Description
The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (98)
page 4 of 5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-8513 | Med | 0.34 | 5.3 | 0.00 | Aug 3, 2025 | A vulnerability, which was classified as problematic, was found in Caixin News App 8.0.1 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.caixin.news. The manipulation leads to improper export of android application components.… | ||
| CVE-2025-8512 | Med | 0.34 | 5.3 | 0.00 | Aug 3, 2025 | A vulnerability, which was classified as problematic, has been found in TVB Big Big Shop App 2.9.0 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component hk.com.tvb.bigbigshop. The manipulation leads to improper export of android… | ||
| CVE-2025-8275 | Med | 0.34 | 5.3 | 0.00 | Jul 28, 2025 | A vulnerability, which was classified as problematic, has been found in bsc Peru Cocktails App 1.0.0 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component bsc.devy.peru_cocktails. The manipulation leads to improper… | ||
| CVE-2025-8258 | Med | 0.34 | 5.3 | 0.00 | Jul 28, 2025 | A vulnerability, which was classified as problematic, has been found in Cool Mo Maigcal Number App up to 1.0.3 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.sdmagic.number. The manipulation leads to improper… | ||
| CVE-2025-8257 | Med | 0.34 | 5.3 | 0.00 | Jul 28, 2025 | A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.maverick.lobby. The manipulation leads to improper export of… | ||
| CVE-2025-8210 | Med | 0.34 | 5.3 | 0.00 | Jul 26, 2025 | A vulnerability was found in Yeelink Yeelight App up to 3.5.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component com.yeelight.cherry. The manipulation leads to improper export of android application… | ||
| CVE-2025-8207 | Med | 0.34 | 5.3 | 0.00 | Jul 26, 2025 | A vulnerability was found in Canara ai1 Mobile Banking App 3.6.23 on Android and classified as problematic. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.canarabank.mobility. The manipulation leads to improper export of android… | ||
| CVE-2025-7940 | Med | 0.34 | 5.3 | 0.00 | Jul 21, 2025 | A vulnerability was found in Genshin Albedo Cat House App 1.0.2 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.house.auscat. The manipulation leads to improper… | ||
| CVE-2025-7893 | Med | 0.34 | 5.3 | 0.00 | Jul 20, 2025 | A vulnerability classified as problematic was found in Foresight News App up to 2.6.4 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml of the component pro.foresightnews.appa. The manipulation leads to improper export of android application… | ||
| CVE-2025-7892 | Med | 0.34 | 5.3 | 0.00 | Jul 20, 2025 | A vulnerability classified as problematic has been found in IDnow App up to 9.6.0 on Android. This affects an unknown part of the file AndroidManifest.xml of the component de.idnow. The manipulation leads to improper export of android application components. Local access is… | ||
| CVE-2025-7891 | Med | 0.34 | 5.3 | 0.00 | Jul 20, 2025 | A vulnerability was found in InstantBits Web Video Cast App up to 5.12.4 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.instantbits.cast.webvideo. The manipulation leads to… | ||
| CVE-2025-7890 | Med | 0.34 | 5.3 | 0.00 | Jul 20, 2025 | A vulnerability was found in Dunamu StockPlus App up to 7.62.10 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.dunamu.stockplus. The manipulation leads to improper… | ||
| CVE-2025-7889 | Med | 0.34 | 5.3 | 0.00 | Jul 20, 2025 | A vulnerability was found in CallApp Caller ID App up to 2.0.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component caller.id.phone.number.block. The manipulation leads to improper export of android… | ||
| CVE-2023-21486 | Med | 0.34 | 5.3 | 0.00 | May 4, 2023 | Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox. | ||
| CVE-2023-21485 | Med | 0.34 | 5.3 | 0.00 | May 4, 2023 | Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox. | ||
| CVE-2026-21081 | Med | 0.33 | — | 0.00 | Aug 10, 2026 | Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-5346 | Med | 0.33 | — | 0.00 | Jul 17, 2025 | Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode… | ||
| CVE-2023-41821 | Med | 0.33 | 5.0 | 0.00 | May 3, 2024 | A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information. | ||
| CVE-2023-41816 | Med | 0.33 | 5.0 | 0.00 | May 3, 2024 | An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database. | ||
| CVE-2023-41829 | Med | 0.33 | 5.0 | 0.00 | Mar 4, 2024 | An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization. |
- risk 0.34cvss 5.3epss 0.00
A vulnerability, which was classified as problematic, was found in Caixin News App 8.0.1 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.caixin.news. The manipulation leads to improper export of android application components.…
- risk 0.34cvss 5.3epss 0.00
A vulnerability, which was classified as problematic, has been found in TVB Big Big Shop App 2.9.0 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component hk.com.tvb.bigbigshop. The manipulation leads to improper export of android…
- risk 0.34cvss 5.3epss 0.00
A vulnerability, which was classified as problematic, has been found in bsc Peru Cocktails App 1.0.0 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component bsc.devy.peru_cocktails. The manipulation leads to improper…
- risk 0.34cvss 5.3epss 0.00
A vulnerability, which was classified as problematic, has been found in Cool Mo Maigcal Number App up to 1.0.3 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.sdmagic.number. The manipulation leads to improper…
- risk 0.34cvss 5.3epss 0.00
A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.maverick.lobby. The manipulation leads to improper export of…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in Yeelink Yeelight App up to 3.5.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component com.yeelight.cherry. The manipulation leads to improper export of android application…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in Canara ai1 Mobile Banking App 3.6.23 on Android and classified as problematic. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.canarabank.mobility. The manipulation leads to improper export of android…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in Genshin Albedo Cat House App 1.0.2 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.house.auscat. The manipulation leads to improper…
- risk 0.34cvss 5.3epss 0.00
A vulnerability classified as problematic was found in Foresight News App up to 2.6.4 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml of the component pro.foresightnews.appa. The manipulation leads to improper export of android application…
- risk 0.34cvss 5.3epss 0.00
A vulnerability classified as problematic has been found in IDnow App up to 9.6.0 on Android. This affects an unknown part of the file AndroidManifest.xml of the component de.idnow. The manipulation leads to improper export of android application components. Local access is…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in InstantBits Web Video Cast App up to 5.12.4 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.instantbits.cast.webvideo. The manipulation leads to…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in Dunamu StockPlus App up to 7.62.10 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.dunamu.stockplus. The manipulation leads to improper…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in CallApp Caller ID App up to 2.0.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component caller.id.phone.number.block. The manipulation leads to improper export of android…
- risk 0.34cvss 5.3epss 0.00
Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
- risk 0.34cvss 5.3epss 0.00
Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
- risk 0.33cvss —epss 0.00
Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
- risk 0.33cvss —epss 0.00
Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode…
- risk 0.33cvss 5.0epss 0.00
A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.
- risk 0.33cvss 5.0epss 0.00
An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database.
- risk 0.33cvss 5.0epss 0.00
An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.