CWE-925: Improper Verification of Intent by Broadcast Receiver
The Android application uses a Broadcast Receiver that receives an Intent but does not properly verify that the Intent came from an authorized source.
3 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-10576 — Unauthorized factory reset of Infinix devices
- CVE-2026-33173 — Rails Active Storage has possible content type bypass via metadata in direct uploads
Recently published
- CVE-2026-33173 — Rails Active Storage has possible content type bypass via metadata in direct uploads
- CVE-2024-10576 — Unauthorized factory reset of Infinix devices