CVE-2025-9102 identifies a security vulnerability in the 1&1 Mail & Media mail.com App 8.8.0 on Android, specifically due to improper export of an Android application component within the AndroidManifest.xml file. This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and potentially leading to high confidentiality impact without affecting integrity or availability. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and no known exploit code exists in common repositories like Metasploit or ExploitDB, nor has it garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.8.0CPE matchmatch criteria | cpe:2.3:a:mail:mail.com:8.8.0:*:*:*:*:android:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.