Fallos del tipo CWE-926

98 resultados

Exportação inadequada de componentes Android

Componentes do app Android (Activities, Services, Broadcast Receivers, Content Providers) são expostos publicamente sem autenticação ou permissões adequadas quando marcados como exportados. Isso permite que apps maliciosos ou terceiros não autorizados invoquem diretamente esses componentes, contornando a lógica de segurança da aplicação.

Ejemplo

Um app bancário exporta uma Activity de confirmação de transação sem proteção. Um malware consegue iniciar essa Activity diretamente, simulando transferências ou acessando dados sensíveis sem passar pela tela de login.

Cómo mitigar

Exporte apenas componentes verdadeiramente necessários (evite android:exported=true no AndroidManifest.xml). Para componentes exportados, implemente verificação de permissões (android:permission), validação de intent e use assinaturas de app para restringir quem pode invocar.

CVE-2025-5346MEDIUMFile removal via path traversal in unsecured broadcast receiver in Bluebird barcode scanner applicationEPSS 0.1%CVE-2023-41816MEDIUM An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a locEPSS 0.1%CVE-2025-9097MEDIUMEuro Information CIC banque et compte en ligne App com.cic_prod.bad AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-9672MEDIUMRejseplanen App de.hafas.android.rejseplanen AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-9673MEDIUMKakao 헤이카카오 Hey Kakao App com.kakao.i.connect AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-9671MEDIUMUAB Paytend App com.passport.cash AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-5500MEDIUMZhenShi Mibro Fit App com.xiaoxun.xunoversea.mibrofit AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-10722MEDIUMSKTLab Mukbee App com.dw.android.mukbee AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-10715MEDIUMAPEUni PTE Exam Practice App com.ape_edication AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-10195MEDIUMSeismic App com.seismic.doccenter AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2026-20470MEDIUMIn Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure EPSS 0.1%CVE-2025-8523MEDIUMRiderLike Fruit Crush-Brain App com.fruitcrush.fun AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2021-25397MEDIUMAn improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of tEPSS 0.1%CVE-2026-68928HIGHAcode: Exported TerminalService (bundled terminal plugin) lets any installed app execute arbitrary shell commands as AcodeEPSS 0.1%CVE-2025-5345MEDIUMExposed AIDL service allowing to read and delete files with system-level privileges in Bluebird filemanager applicationEPSS 0.1%CVE-2025-8275MEDIUMbsc Peru Cocktails App bsc.devy.peru_cocktails AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-8524MEDIUMBoquan DotWallet App com.boquanhash.dotwallet AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-8512MEDIUMTVB Big Big Shop App hk.com.tvb.bigbigshop AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-8513MEDIUMCaixin News App com.caixin.news AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2026-81301HIGHEkia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file accessEPSS 0.1%