The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.
Volume of CVEs assigned to CWE-926 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
82 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-54318HIGH Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no | Jun 23, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-12960MEDIUM An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS | Jul 3, 2026 | 6.0 | 29 | NO | NO |
CVE-2026-57848MEDIUM Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts the | Jul 18, 2026 | 5.5 | 28 | NO | NO |
CVE-2025-68713HIGH An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no perm | Jun 15, 2026 | 8.0 | 27 | NO | NO |
CVE-2026-44279MEDIUM An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all ver | May 12, 2026 | 5.5 | 25 | NO | NO |
CVE-2025-15464HIGH Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls. | Jan 8, 2026 | 7.5 | 25 | NO | NO |
CVE-2024-13917HIGH An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data.
| May 30, 2025 | 8.3 | 25 | NO | NO |
CVE-2021-25400HIGH Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action. | Jun 11, 2021 | 7.8 | 25 | NO | NO |
CVE-2026-3291MEDIUM Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing u | May 6, 2026 | 5.5 | 24 | NO | NO |
CVE-2025-32347HIGH In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of pr | Sep 4, 2025 | 7.8 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.