# CVE-2025-15464

## Summary

- **CVE ID:** CVE-2025-15464
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-926
- **Published:** Jan 8, 2026
- **Last Modified:** Mar 12, 2026

## Description

Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.

## Affected Products

- yintibao — Fun Print Mobile (6.05.15)

## References

- [CNA](https://korelogic.com/Resources/Advisories/KL-001-2026-001.txt)
- [CISA-ADP](https://korelogic.com/Resources/Advisories/KL-001-2026-001.poc.js.txt)
- [CVE](http://seclists.org/fulldisclosure/2026/Jan/12)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.53%
- **EPSS Percentile:** 42.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._