CWE-926: Improper Export of Android Application Components
The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.
83 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-5344 — Exposed AIDL service allowing for tampering of system secure settings in Bluebird kiosk application
- CVE-2024-13917 — Intent Injection in Kruger&Matz AppLock application
- CVE-2024-13916 — Exposure of Applications' Encryption PINs in Kruger&Matz AppLock
- CVE-2024-13915 — Unrestricted Access to Exported Service in com.pri.factorytest
- CVE-2025-27599 — Element X Android vulnerable to loading malicious web pages via received intent
- CVE-2025-5345 — Exposed AIDL service allowing to read and delete files with system-level privileges in Bluebird filemanager application
- CVE-2026-54318 — Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location
- CVE-2026-3291 — Samsung Print Service Plugin – Potential Information Disclosure
- CVE-2026-57848 — Stoat for Android Internal File Disclosure via Exported ShareTargetActivity URI Validation
- CVE-2026-47361 — BubbleChatActivity in the Datadog Android application is declared android:exported="true" with no permission guard and a
- CVE-2025-9695 — GalleryVault Gallery Vault App com.thinkyeah.galleryvault AndroidManifest.xml improper export of android application components
- CVE-2025-9677 — Modo Legend of the Phoenix com.duige.hzw.multilingual AndroidManifest.xml improper export of android application components
- CVE-2025-9676 — NCSOFT Universe App com.ncsoft.universeapp AndroidManifest.xml improper export of android application components
- CVE-2025-9675 — Voice Changer App com.tuyangkeji.changevoice AndroidManifest.xml improper export of android application components
- CVE-2025-9674 — Transbyte Scooper News App com.hatsune.eagleee AndroidManifest.xml improper export of android application components
- CVE-2025-9673 — Kakao 헤이카카오 Hey Kakao App com.kakao.i.connect AndroidManifest.xml improper export of android application components
- CVE-2025-9672 — Rejseplanen App de.hafas.android.rejseplanen AndroidManifest.xml improper export of android application components
- CVE-2025-9671 — UAB Paytend App com.passport.cash AndroidManifest.xml improper export of android application components
- CVE-2025-9135 — Verkehrsauskunft Österreich SmartRide/cleVVVer/BusBahnBim/Salzburg Verkehr AndroidManifest.xml improper export of android application components
- CVE-2025-9134 — AfterShip Package Tracker App com.aftership.AfterShip AndroidManifest.xml improper export of android application components
Recently published
- CVE-2026-20516 — In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denia
- CVE-2026-44965 — Six Android App Widget configuration activities in the Datadog Android application are declared android:exported="true"
- CVE-2026-47363 — The launcher activity AppActivity in the Datadog Android application is declared android:exported="true" with launchMode
- CVE-2026-47361 — BubbleChatActivity in the Datadog Android application is declared android:exported="true" with no permission guard and a
- CVE-2026-18604 — textPlus Text Message and Call App com.gogii.textplus DialerActivity improper export of android application components
- CVE-2026-20470 — In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf
- CVE-2026-57848 — Stoat for Android Internal File Disclosure via Exported ShareTargetActivity URI Validation
- CVE-2026-12960 — An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o
- CVE-2026-54318 — Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location
- CVE-2026-44279 — A improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiT
- CVE-2026-3291 — Samsung Print Service Plugin – Potential Information Disclosure
- CVE-2025-15464 — KL-001-2026-01: yintibao Fun Print Mobile Unauthorized Access via Context Hijacking
- CVE-2025-14517 — Yalantis uCrop AndroidManifest.xml UCropActivity improper export of android application components
- CVE-2025-10722 — SKTLab Mukbee App com.dw.android.mukbee AndroidManifest.xml improper export of android application components
- CVE-2025-10721 — Webull Investing & Trading App AndroidManifest.xml improper export of android application components
- CVE-2025-10718 — Ooma Office Business Phone App com.ooma.office2 improper export of android application components
- CVE-2025-10717 — intsig CamScanner App com.intsig.camscanner AndroidManifest.xml improper export of android application components
- CVE-2025-10716 — Creality Cloud App com.cxsw.sdprinter AndroidManifest.xml improper export of android application components
- CVE-2025-10715 — APEUni PTE Exam Practice App com.ape_edication AndroidManifest.xml improper export of android application components
- CVE-2025-10195 — Seismic App com.seismic.doccenter AndroidManifest.xml improper export of android application components