VYPR

CWE-926

Improper Export of Android Application Components

VariantIncomplete

Description

The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (90)

page 5 of 5
  • CVE-2021-25391MedJun 11, 2021
    risk 0.26cvss 4.0epss 0.00

    Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

  • CVE-2021-25390MedJun 11, 2021
    risk 0.26cvss 4.0epss 0.00

    Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

  • CVE-2021-25379MedApr 9, 2021
    risk 0.26cvss 4.0epss 0.00

    Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.

  • CVE-2021-25527LowDec 8, 2021
    risk 0.25cvss 3.8epss 0.00

    Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.

  • CVE-2023-44129LowSep 27, 2023
    risk 0.23cvss 3.6epss 0.00

    The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity. The attacker can abuse this functionality by launching this activity…

  • CVE-2024-3479LowMay 3, 2024
    risk 0.18cvss 2.8epss 0.00

    An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data.

  • CVE-2024-27086LowApr 16, 2024
    risk 0.18cvss 3.9epss 0.00

    The MSAL library enabled acquisition of security tokens to call protected APIs. MSAL.NET applications targeting Xamarin Android and .NET Android (e.g., MAUI) using the library from versions 4.48.0 to 4.60.0 are impacted by a low severity vulnerability. A malicious application…

  • CVE-2026-20470MedAug 3, 2026
    risk 0.00cvss 6.2epss 0.00

    In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189.

  • CVE-2026-57848MedJul 18, 2026
    risk 0.00cvss 5.5epss 0.00

    Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts the file to share as a URI supplied through the android.intent.extra.STREAM extra. The activity does…

  • CVE-2026-12960MedJul 3, 2026
    risk 0.00cvss epss 0.00

    An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Security Update for ASUS Router Android App '…