Fallos del tipo CWE-926

98 resultados

Exportação inadequada de componentes Android

Componentes do app Android (Activities, Services, Broadcast Receivers, Content Providers) são expostos publicamente sem autenticação ou permissões adequadas quando marcados como exportados. Isso permite que apps maliciosos ou terceiros não autorizados invoquem diretamente esses componentes, contornando a lógica de segurança da aplicação.

Ejemplo

Um app bancário exporta uma Activity de confirmação de transação sem proteção. Um malware consegue iniciar essa Activity diretamente, simulando transferências ou acessando dados sensíveis sem passar pela tela de login.

Cómo mitigar

Exporte apenas componentes verdadeiramente necessários (evite android:exported=true no AndroidManifest.xml). Para componentes exportados, implemente verificação de permissões (android:permission), validação de intent e use assinaturas de app para restringir quem pode invocar.

CVE-2021-25400Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.EPSS 0.2%CVE-2025-8745MEDIUMWeee RICEPO App com.ricepo.app AndroidManifest.xml improper export of android application componentsEPSS 0.2%CVE-2025-9102MEDIUM1&1 Mail & Media mail.com App com.mail.mobile.android.mail AndroidManifest.xml improper export of android application componentsEPSS 0.2%CVE-2021-25527LOWImproper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to accesEPSS 0.2%CVE-2025-8210MEDIUMYeelink Yeelight App com.yeelight.cherry AndroidManifest.xml improper export of android application componentsEPSS 0.2%CVE-2025-8207MEDIUMCanara ai1 Mobile Banking App com.canarabank.mobility AndroidManifest.xml improper export of android application componentsEPSS 0.2%CVE-2025-9695MEDIUMGalleryVault Gallery Vault App com.thinkyeah.galleryvault AndroidManifest.xml improper export of android application componentsEPSS 0.2%CVE-2025-8707MEDIUMHuuge Box App com.huuge.game.zjbox AndroidManifest.xml improper export of android application componentsEPSS 0.2%CVE-2021-25379MEDIUMIntent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.EPSS 0.2%CVE-2025-8257MEDIUMLobby Universe Lobby App com.maverick.lobby AndroidManifest.xml improper export of android application componentsEPSS 0.2%CVE-2025-8258MEDIUMCool Mo Maigcal Number App com.sdmagic.number AndroidManifest.xml improper export of android application componentsEPSS 0.2%CVE-2026-57848MEDIUMStoat for Android Internal File Disclosure via Exported ShareTargetActivity URI ValidationEPSS 0.2%CVE-2021-25526MEDIUMIntent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.EPSS 0.2%CVE-2024-13917HIGHIntent Injection in Kruger&Matz AppLock applicationEPSS 0.2%CVE-2024-13915MEDIUMUnrestricted Access to Exported Service in com.pri.factorytestEPSS 0.2%CVE-2024-27086LOWMSAL.NET applications targeting Xamarin Android and .NET Android (MAUI) susceptible to local denial of serviceEPSS 0.2%CVE-2023-41960HIGHThe vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the AndrEPSS 0.2%CVE-2024-13916MEDIUMExposure of Applications' Encryption PINs in Kruger&Matz AppLockEPSS 0.2%CVE-2026-47361MEDIUMIn versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEEPSS 0.2%CVE-2025-9098MEDIUMElseplus File Recovery App AndroidManifest.xml improper export of android application componentsEPSS 0.2%