VYPR

CWE-926

Improper Export of Android Application Components

VariantIncomplete

Description

The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (90)

page 4 of 5
  • CVE-2025-7893MedJul 20, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability classified as problematic was found in Foresight News App up to 2.6.4 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml of the component pro.foresightnews.appa. The manipulation leads to improper export of android application…

  • CVE-2025-7892MedJul 20, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability classified as problematic has been found in IDnow App up to 9.6.0 on Android. This affects an unknown part of the file AndroidManifest.xml of the component de.idnow. The manipulation leads to improper export of android application components. Local access is…

  • CVE-2025-7891MedJul 20, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in InstantBits Web Video Cast App up to 5.12.4 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.instantbits.cast.webvideo. The manipulation leads to…

  • CVE-2025-7890MedJul 20, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in Dunamu StockPlus App up to 7.62.10 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.dunamu.stockplus. The manipulation leads to improper…

  • CVE-2025-7889MedJul 20, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in CallApp Caller ID App up to 2.0.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component caller.id.phone.number.block. The manipulation leads to improper export of android…

  • CVE-2023-21486MedMay 4, 2023
    risk 0.34cvss 5.3epss 0.00

    Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.

  • CVE-2023-21485MedMay 4, 2023
    risk 0.34cvss 5.3epss 0.00

    Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.

  • CVE-2026-21081MedAug 10, 2026
    risk 0.33cvss epss 0.00

    Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

  • CVE-2025-5346MedJul 17, 2025
    risk 0.33cvss epss 0.00

    Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode…

  • CVE-2023-41821MedMay 3, 2024
    risk 0.33cvss 5.0epss 0.00

    A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information. 

  • CVE-2023-41816MedMay 3, 2024
    risk 0.33cvss 5.0epss 0.00

    An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database. 

  • CVE-2023-41829MedMar 4, 2024
    risk 0.33cvss 5.0epss 0.00

    An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.

  • CVE-2023-41827MedMar 4, 2024
    risk 0.33cvss 5.1epss 0.00

    An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI.

  • CVE-2023-44121MedSep 27, 2023
    risk 0.33cvss 5.0epss 0.00

    The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device by sending a broadcast with the action…

  • CVE-2023-41822MedMay 3, 2024
    risk 0.31cvss 4.8epss 0.00

    An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands. 

  • CVE-2023-41823MedMay 3, 2024
    risk 0.29cvss 4.4epss 0.00

    An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities. 

  • CVE-2024-6051MedSep 30, 2024
    risk 0.28cvss epss 0.00

    Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection and to manipulate the view of a vulnerable application.This issue affects Redlink SDK versions through 1.13.

  • CVE-2021-4438MedApr 7, 2024
    risk 0.27cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, has been found in kyivstarteam react-native-sms-user-consent up to 1.1.4 on Android. Affected by this issue is the function registerReceiver of the file android/src/main/java/ua/kyivstar/reactnativesmsuserconsent/SmsUserConsentMo…

  • CVE-2022-24929MedMar 10, 2022
    risk 0.27cvss 4.1epss 0.00

    Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.

  • CVE-2021-25526MedDec 8, 2021
    risk 0.26cvss 4.0epss 0.00

    Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.