Fallos del tipo CWE-926

84 resultados

Exportação inadequada de componentes Android

Componentes do app Android (Activities, Services, Broadcast Receivers, Content Providers) são expostos publicamente sem autenticação ou permissões adequadas quando marcados como exportados. Isso permite que apps maliciosos ou terceiros não autorizados invoquem diretamente esses componentes, contornando a lógica de segurança da aplicação.

Ejemplo

Um app bancário exporta uma Activity de confirmação de transação sem proteção. Um malware consegue iniciar essa Activity diretamente, simulando transferências ou acessando dados sensíveis sem passar pela tela de login.

Cómo mitigar

Exporte apenas componentes verdadeiramente necessários (evite android:exported=true no AndroidManifest.xml). Para componentes exportados, implemente verificação de permissões (android:permission), validação de intent e use assinaturas de app para restringir quem pode invocar.

CVE-2025-15464HIGHKL-001-2026-01: yintibao Fun Print Mobile Unauthorized Access via Context HijackingEPSS 0.5%CVE-2025-27599MEDIUMElement X Android vulnerable to loading malicious web pages via received intentEPSS 0.3%CVE-2025-7891MEDIUMInstantBits Web Video Cast App com.instantbits.cast.webvideo AndroidManifest.xml improper export of android application componentsEPSS 0.3%CVE-2025-68713HIGHAn issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allEPSS 0.3%CVE-2025-9135MEDIUMVerkehrsauskunft Österreich SmartRide/cleVVVer/BusBahnBim/Salzburg Verkehr AndroidManifest.xml improper export of android application componentsEPSS 0.3%CVE-2025-7890MEDIUMDunamu StockPlus App com.dunamu.stockplus AndroidManifest.xml improper export of android application componentsEPSS 0.3%CVE-2025-7892MEDIUMIDnow App de.idnow AndroidManifest.xml improper export of android application componentsEPSS 0.3%CVE-2025-7893MEDIUMForesight News App pro.foresightnews.appa AndroidManifest.xml improper export of android application componentsEPSS 0.3%CVE-2025-9676MEDIUMNCSOFT Universe App com.ncsoft.universeapp AndroidManifest.xml improper export of android application componentsEPSS 0.3%CVE-2025-9677MEDIUMModo Legend of the Phoenix com.duige.hzw.multilingual AndroidManifest.xml improper export of android application componentsEPSS 0.3%CVE-2025-9674MEDIUMTransbyte Scooper News App com.hatsune.eagleee AndroidManifest.xml improper export of android application componentsEPSS 0.3%CVE-2025-9675MEDIUMVoice Changer App com.tuyangkeji.changevoice AndroidManifest.xml improper export of android application componentsEPSS 0.3%CVE-2021-4438MEDIUMkyivstarteam react-native-sms-user-consent SmsUserConsentModule.kt registerReceiver improper export of android application componentsEPSS 0.3%CVE-2025-9134MEDIUMAfterShip Package Tracker App com.aftership.AfterShip AndroidManifest.xml improper export of android application componentsEPSS 0.3%CVE-2024-36437MEDIUMThe com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any installed application (wiEPSS 0.3%CVE-2025-9093MEDIUMBuzzFeed App com.buzzfeed.android AndroidManifest.xml improper export of android application componentsEPSS 0.3%CVE-2023-21485MEDIUMImproper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows phEPSS 0.3%CVE-2023-21486MEDIUMImproper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows phEPSS 0.3%CVE-2021-25400Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.EPSS 0.2%CVE-2025-7889MEDIUMCallApp Caller ID App caller.id.phone.number.block AndroidManifest.xml improper export of android application componentsEPSS 0.2%