CWE-926— Improper Export of Android Application Components
The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.— MITRE CWE catalog
99 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-926page 1 of 2
- CVE-2026-68928HIGHCVSS 8.6EG 8.62026-09-18
Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src…
- CVE-2026-81301HIGHCVSS 8.5EG 8.52026-09-14
Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps the caller-controlled URI path directly to a filesystem path and p…
- CVE-2025-5344HIGHCVSS 8.5EG 8.52025-07-17
Bluebird devices contain a pre-loaded kiosk application. This application exposes an unsecured service provider "com.bluebird.kiosk.launcher.IpartnerKioskRemoteService". A local attacker can bind to the AIDL-type service to modify device's…
- CVE-2024-13917HIGHCVSS 8.3EG 8.32025-05-30
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any …
- CVE-2025-68713HIGHCVSS 8.0EG 8.02026-06-15
An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into the app's s…
- CVE-2025-32347HIGHCVSS 7.8EG 7.82025-09-04
In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
- CVE-2021-25400HIGHCVSS 7.8EG 7.82021-06-11
Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.
- CVE-2025-15464HIGHCVSS 7.5EG 7.52026-01-08
Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.
- CVE-2026-45528HIGHCVSS 7.3EG 7.32026-09-08
In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User i…
- CVE-2026-18994HIGHCVSS 7.1EG 7.12026-09-10
A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files with…
- CVE-2026-21059HIGHCVSS 7.1EG 7.12026-08-10
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
- CVE-2026-54318HIGHCVSS 7.1EG 7.12026-06-23
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissio…
- CVE-2021-25388HIGHCVSS 7.1EG 7.12021-06-11
Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.
- CVE-2023-41960HIGHCVSS 3.3EG 7.12023-10-25
The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive settings of the Android Client application i…
- CVE-2024-13916MEDIUMCVSS 6.9EG 6.92025-05-30
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.android.providers.settings.fingerprint.Pri…
- CVE-2024-13915MEDIUMCVSS 6.9EG 6.92025-05-30
Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process. The application "com.pri.factorytest" (version name: 1.0, version cod…
- CVE-2021-25397MEDIUMCVSS 6.8EG 6.82021-06-11
An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.
- CVE-2025-27599MEDIUMCVSS 6.5EG 6.52025-04-18
Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a webpage with similar…
- CVE-2024-36437MEDIUMCVSS 6.5EG 6.52025-02-03
The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via th…
- CVE-2026-47361MEDIUMCVSS 6.4EG 6.42026-08-07
In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the activity closes and no in-process sessio…
- CVE-2026-47363MEDIUMCVSS 6.3EG 6.32026-08-07
In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app int…
- CVE-2025-5345MEDIUMCVSS 6.3EG 6.32025-07-17
Bluebird devices contain a pre-loaded file manager application. This application exposes an unsecured service provider "com.bluebird.system.koreanpost.IsdcardRemoteService". A local attacker can bind to the AIDL-type service to copy and de…
- CVE-2023-44121MEDIUMCVSS 6.3EG 6.32023-09-27
The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device…
- CVE-2026-20470MEDIUMCVSS 6.2EG 6.22026-08-03
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Pa…
- CVE-2026-21063MEDIUMCVSS 6.1EG 6.12026-08-10
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.
- CVE-2026-12960MEDIUMCVSS 6.0EG 6.02026-07-03
An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Securit…
- CVE-2026-21113MEDIUMCVSS 5.5EG 5.52026-09-09
Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.
- CVE-2026-21108MEDIUMCVSS 5.5EG 5.52026-09-09
Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.
- CVE-2026-20516MEDIUMCVSS 5.5EG 5.52026-09-07
In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS1106…
- CVE-2026-44965MEDIUMCVSS 5.5EG 5.52026-08-07
In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, …
- CVE-2026-57848MEDIUMCVSS 5.5EG 5.52026-07-18
Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts the file to share as a URI supplied through the android.intent…
- CVE-2026-44279MEDIUMCVSS 5.5EG 5.52026-05-12
An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to disclose information via an exp…
- CVE-2026-3291MEDIUMCVSS 5.5EG 5.52026-05-06
Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.
- CVE-2025-9695MEDIUMCVSS 5.5EG 5.52025-08-30
A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.thinkyeah.galleryvault. The manipulation lea…
- CVE-2025-9677MEDIUMCVSS 5.5EG 5.52025-08-29
A security flaw has been discovered in Modo Legend of the Phoenix up to 1.0.5. The affected element is an unknown function of the file AndroidManifest.xml of the component com.duige.hzw.multilingual. The manipulation results in improper ex…
- CVE-2025-9676MEDIUMCVSS 5.5EG 5.52025-08-29
A vulnerability was identified in NCSOFT Universe App up to 1.3.0. Impacted is an unknown function of the file AndroidManifest.xml of the component com.ncsoft.universeapp. The manipulation leads to improper export of android application co…
- CVE-2025-9675MEDIUMCVSS 5.5EG 5.52025-08-29
A vulnerability was determined in Voice Changer App up to 1.1.0. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.tuyangkeji.changevoice. Executing manipulation can lead to improper export of …
- CVE-2025-9674MEDIUMCVSS 5.5EG 5.52025-08-29
A flaw has been found in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.hatsune.eagleee. This manipulation causes improper export o…
- CVE-2025-9135MEDIUMCVSS 5.5EG 5.52025-08-19
A vulnerability was detected in Verkehrsauskunft Österreich SmartRide, cleVVVer, BusBahnBim and Salzburg Verkehr up to 12.1.1(258) on Android. The impacted element is an unknown function of the file AndroidManifest.xml. The manipulation r…
- CVE-2025-9134MEDIUMCVSS 5.5EG 5.52025-08-19
A security vulnerability has been detected in AfterShip Package Tracker App up to 5.24.1 on Android. The affected element is an unknown function of the file AndroidManifest.xml of the component com.aftership.AfterShip. The manipulation lea…
- CVE-2025-9102MEDIUMCVSS 5.5EG 5.52025-08-18
A security vulnerability has been detected in 1&1 Mail & Media mail.com App 8.8.0 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.mail.mobile.android.mail. The manipulation leads to improper…
- CVE-2025-9093MEDIUMCVSS 5.5EG 5.52025-08-17
A security vulnerability has been detected in BuzzFeed App 2024.9 on Android. This affects an unknown part of the file AndroidManifest.xml of the component com.buzzfeed.android. The manipulation leads to improper export of android applicat…
- CVE-2025-8745MEDIUMCVSS 5.5EG 5.52025-08-09
A vulnerability, which was classified as problematic, has been found in Weee RICEPO App 6.17.77 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.ricepo.app. The manipulation leads …
- CVE-2025-8707MEDIUMCVSS 5.5EG 5.52025-08-08
A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been classified as problematic. This affects an unknown part of the file AndroidManifest.xml of the component com.huuge.game.zjbox. The manipulation leads to improper expo…
- CVE-2025-7893MEDIUMCVSS 5.5EG 5.52025-07-20
A vulnerability classified as problematic was found in Foresight News App up to 2.6.4 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml of the component pro.foresightnews.appa. The manipulation leads to im…
- CVE-2025-7892MEDIUMCVSS 5.5EG 5.52025-07-20
A vulnerability classified as problematic has been found in IDnow App up to 9.6.0 on Android. This affects an unknown part of the file AndroidManifest.xml of the component de.idnow. The manipulation leads to improper export of android appl…
- CVE-2025-7891MEDIUMCVSS 5.5EG 5.52025-07-20
A vulnerability was found in InstantBits Web Video Cast App up to 5.12.4 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.instantbits.ca…
- CVE-2025-7890MEDIUMCVSS 5.5EG 5.52025-07-20
A vulnerability was found in Dunamu StockPlus App up to 7.62.10 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.dunamu.stockpl…
- CVE-2025-7889MEDIUMCVSS 5.5EG 5.52025-07-20
A vulnerability was found in CallApp Caller ID App up to 2.0.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component caller.id.phone.number.block. The manipulati…
- CVE-2025-20934MEDIUMCVSS 5.5EG 5.52025-04-08
Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.
Map vulnerabilities like CWE-926 to your infrastructure
EchelonGraph correlates every CVE — across CWE-926 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →