CVE-2025-7891 is a medium-severity vulnerability affecting InstantBits Web Video Cast App up to version 5.12.4 on Android, stemming from improper export of Android application components within the AndroidManifest.xml file. This local attack requires low complexity and low privileges, potentially leading to high confidentiality impact without affecting integrity or availability. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and it lacks community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.12.4CPE matchmatch criteria | cpe:2.3:a:instantbits:web_video_cast:*:*:*:*:*:android:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.