Falhas do tipo CWE-926

98 resultados

Exportação Inadequada de Componentes Android

Quando um app Android expõe Activities, Services, Broadcast Receivers ou Content Providers sem restringir o acesso, qualquer outro app no dispositivo consegue ativar e interagir com esses componentes. Isso permite que atacantes invoguem funcionalidades sensíveis, acessem dados privados ou sequestrem o fluxo de execução da aplicação.

Exemplo

Um app de banco define um Service para processar transferências sem o atributo android:exported="false" no AndroidManifest.xml. Um malware consegue enviar intents para esse Service e disparar transferências não autorizadas ou extrair dados da sessão do usuário.

Como mitigar

Marque android:exported="false" para todos os componentes que não precisam ser acessados por apps externos. Para componentes que precisam ser públicos, use permission-level em <permission> ou implemente validação de intent assinada com a chave privada do app para confirmar a origem da requisição.

CVE-2025-5346MEDIUMFile removal via path traversal in unsecured broadcast receiver in Bluebird barcode scanner applicationEPSS 0.1%CVE-2023-41816MEDIUM An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a locEPSS 0.1%CVE-2025-9097MEDIUMEuro Information CIC banque et compte en ligne App com.cic_prod.bad AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-9672MEDIUMRejseplanen App de.hafas.android.rejseplanen AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-9673MEDIUMKakao 헤이카카오 Hey Kakao App com.kakao.i.connect AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-9671MEDIUMUAB Paytend App com.passport.cash AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-5500MEDIUMZhenShi Mibro Fit App com.xiaoxun.xunoversea.mibrofit AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-10722MEDIUMSKTLab Mukbee App com.dw.android.mukbee AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-10715MEDIUMAPEUni PTE Exam Practice App com.ape_edication AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-10195MEDIUMSeismic App com.seismic.doccenter AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2026-20470MEDIUMIn Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure EPSS 0.1%CVE-2025-8523MEDIUMRiderLike Fruit Crush-Brain App com.fruitcrush.fun AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2021-25397MEDIUMAn improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of tEPSS 0.1%CVE-2026-68928HIGHAcode: Exported TerminalService (bundled terminal plugin) lets any installed app execute arbitrary shell commands as AcodeEPSS 0.1%CVE-2025-5345MEDIUMExposed AIDL service allowing to read and delete files with system-level privileges in Bluebird filemanager applicationEPSS 0.1%CVE-2025-8275MEDIUMbsc Peru Cocktails App bsc.devy.peru_cocktails AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-8524MEDIUMBoquan DotWallet App com.boquanhash.dotwallet AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-8512MEDIUMTVB Big Big Shop App hk.com.tvb.bigbigshop AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2025-8513MEDIUMCaixin News App com.caixin.news AndroidManifest.xml improper export of android application componentsEPSS 0.1%CVE-2026-81301HIGHEkia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file accessEPSS 0.1%