CWE-926— Improper Export of Android Application Components
The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.— MITRE CWE catalog
99 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-926page 2 of 2
- CVE-2023-20962MEDIUMCVSS 5.5EG 5.52023-03-24
In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional executi…
- CVE-2021-25526MEDIUMCVSS 4.0EG 5.52021-12-08
Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.
- CVE-2026-18604MEDIUMCVSS 5.3EG 5.32026-08-03
A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. Such manipulation leads to improper export of android application co…
- CVE-2025-14517MEDIUMCVSS 5.3EG 5.32025-12-11
A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity of the file AndroidManifest.xml. Executing manipulation can lead to improper export of android application components. The attack can only b…
- CVE-2025-10722MEDIUMCVSS 5.3EG 5.32025-09-19
A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android. This affects an unknown function of the file AndroidManifest.xml of the component com.dw.android.mukbee. The manipulation results in improper export of android applicat…
- CVE-2025-10721MEDIUMCVSS 5.3EG 5.32025-09-19
A vulnerability was determined in Webull Investing & Trading App 11.2.5.63 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml. This manipulation causes improper export of android application components. The…
- CVE-2025-10718MEDIUMCVSS 5.3EG 5.32025-09-19
A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android. This affects an unknown part of the component com.ooma.office2. The manipulation results in improper export of android application components. The attack n…
- CVE-2025-10717MEDIUMCVSS 5.3EG 5.32025-09-19
A vulnerability has been found in intsig CamScanner App 6.91.1.5.250711 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.intsig.camscanner. The manipulation leads to impr…
- CVE-2025-10716MEDIUMCVSS 5.3EG 5.32025-09-19
A flaw has been found in Creality Cloud App up to 6.1.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.cxsw.sdprinter. Executing manipulation can lead to improper…
- CVE-2025-10715MEDIUMCVSS 5.3EG 5.32025-09-19
A security flaw has been discovered in APEUni PTE Exam Practice App up to 10.8.0 on Android. The impacted element is an unknown function of the file AndroidManifest.xml of the component com.ape_edication. The manipulation results in improp…
- CVE-2025-10195MEDIUMCVSS 5.3EG 5.32025-09-10
A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.seismic.doccenter. Such manipulation leads to improper export of android application compo…
- CVE-2025-5500MEDIUMCVSS 5.3EG 5.32025-09-09
A flaw has been found in ZhenShi Mibro Fit App 1.6.3.17499 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.xiaoxun.xunoversea.mibrofit. This manipulation causes improper export of android a…
- CVE-2025-9673MEDIUMCVSS 5.3EG 5.32025-08-29
A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.kakao.i.connect. The manipulation …
- CVE-2025-9672MEDIUMCVSS 5.3EG 5.32025-08-29
A security vulnerability has been detected in Rejseplanen App up to 8.2.2. Affected is an unknown function of the file AndroidManifest.xml of the component de.hafas.android.rejseplanen. The manipulation leads to improper export of android …
- CVE-2025-9671MEDIUMCVSS 5.3EG 5.32025-08-29
A weakness has been identified in UAB Paytend App up to 2.1.9 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.passport.cash. Executing manipulation can lead to improper export of android ap…
- CVE-2025-9098MEDIUMCVSS 5.3EG 5.32025-08-18
A vulnerability was determined in Elseplus File Recovery App 4.4.21 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml. The manipulation leads to improper export of android application componen…
- CVE-2025-9097MEDIUMCVSS 5.3EG 5.32025-08-18
A vulnerability was found in Euro Information CIC banque et compte en ligne App 12.56.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.cic_prod.bad. The manipulat…
- CVE-2025-8524MEDIUMCVSS 5.3EG 5.32025-08-04
A vulnerability was found in Boquan DotWallet App 2.15.2 on Android and classified as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.boquanhash.dotwallet. The manipula…
- CVE-2025-8523MEDIUMCVSS 5.3EG 5.32025-08-04
A vulnerability has been found in RiderLike Fruit Crush-Brain App 1.0 on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.fruitcrush.fun.…
- CVE-2025-8513MEDIUMCVSS 5.3EG 5.32025-08-03
A vulnerability, which was classified as problematic, was found in Caixin News App 8.0.1 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.caixin.news. The manipulation leads to improper expor…
- CVE-2025-8512MEDIUMCVSS 5.3EG 5.32025-08-03
A vulnerability, which was classified as problematic, has been found in TVB Big Big Shop App 2.9.0 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component hk.com.tvb.bigbigshop. The manipulat…
- CVE-2025-8275MEDIUMCVSS 5.3EG 5.32025-07-28
A vulnerability, which was classified as problematic, has been found in bsc Peru Cocktails App 1.0.0 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component bsc.devy.peru_cocktails.…
- CVE-2025-8258MEDIUMCVSS 5.3EG 5.32025-07-28
A vulnerability, which was classified as problematic, has been found in Cool Mo Maigcal Number App up to 1.0.3 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.sdmagic.nu…
- CVE-2025-8257MEDIUMCVSS 5.3EG 5.32025-07-28
A vulnerability classified as problematic was found in Lobby Universe Lobby App up to 2.8.0 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.maverick.lobby. The man…
- CVE-2025-7940MEDIUMCVSS 5.3EG 5.32025-07-21
A vulnerability was found in Genshin Albedo Cat House App 1.0.2 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.house.auscat. …
- CVE-2021-4438MEDIUMCVSS 5.3EG 5.32024-04-07
A vulnerability, which was classified as critical, has been found in kyivstarteam react-native-sms-user-consent up to 1.1.4 on Android. Affected by this issue is the function registerReceiver of the file android/src/main/java/ua/kyivstar/r…
- CVE-2023-21486MEDIUMCVSS 5.3EG 5.32023-05-04
Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
- CVE-2023-21485MEDIUMCVSS 5.3EG 5.32023-05-04
Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
- CVE-2025-8210MEDIUMCVSS 4.4EG 5.32025-07-26
A vulnerability was found in Yeelink Yeelight App up to 3.5.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component com.yeelight.cherry. The manipulation leads t…
- CVE-2025-8207MEDIUMCVSS 4.4EG 5.32025-07-26
A vulnerability was found in Canara ai1 Mobile Banking App 3.6.23 on Android and classified as problematic. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.canarabank.mobility. The manipulati…
- CVE-2026-21081MEDIUMCVSS 5.1EG 5.12026-08-10
Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
- CVE-2025-5346MEDIUMCVSS 5.1EG 5.12025-07-17
Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containi…
- CVE-2023-41827MEDIUMCVSS 5.1EG 5.12024-03-04
An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI.
- CVE-2023-41821MEDIUMCVSS 5.0EG 5.02024-05-03
A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.
- CVE-2023-41816MEDIUMCVSS 5.0EG 5.02024-05-03
An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database.
- CVE-2023-41829MEDIUMCVSS 5.0EG 5.02024-03-04
An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.
- CVE-2023-41822MEDIUMCVSS 4.8EG 4.82024-05-03
An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands.
- CVE-2023-41823MEDIUMCVSS 4.4EG 4.42024-05-03
An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities.
- CVE-2024-6051MEDIUMCVSS 4.3EG 4.32024-09-30
Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection and to manipulate the view of a vulnerable application.This issue affects Redlink SDK versions through 1.13.
- CVE-2022-24929MEDIUMCVSS 4.1EG 4.12022-03-10
Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.
- CVE-2023-30718MEDIUMCVSS 4.0EG 4.02023-09-06
Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity prior to SMR Sep-2023 Release 1 allows local attacker to change a Auto Hotspot setting.
- CVE-2021-25391MEDIUMCVSS 4.0EG 4.02021-06-11
Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
- CVE-2021-25390MEDIUMCVSS 4.0EG 4.02021-06-11
Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
- CVE-2021-25379MEDIUMCVSS 4.0EG 4.02021-04-09
Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.
- CVE-2024-27086LOWCVSS 3.9EG 3.92024-04-16
The MSAL library enabled acquisition of security tokens to call protected APIs. MSAL.NET applications targeting Xamarin Android and .NET Android (e.g., MAUI) using the library from versions 4.48.0 to 4.60.0 are impacted by a low severity v…
- CVE-2021-25527LOWCVSS 3.8EG 3.82021-12-08
Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.
- CVE-2023-44129LOWCVSS 3.3EG 3.62023-09-27
The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity. The attacker can abuse this …
- CVE-2024-3479LOWCVSS 2.8EG 2.82024-05-03
An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data.
- CVE-2026-86701LOWCVSS 2.5EG 2.52026-09-15
Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device may exploit the affected component via an Intent, pot…
Map vulnerabilities like CWE-926 to your infrastructure
EchelonGraph correlates every CVE — across CWE-926 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →