The Android application uses an implicit intent for transmitting sensitive data to other applications.
Volume of CVEs assigned to CWE-927 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4903HIGH A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function. The manipulation leads to use of implicit intent for sensit | Feb 10, 2023 | 8.1 | 25 | NO | NO |
CVE-2025-48558HIGH In multiple functions of BatteryService.java, there is a possible way to hijack implicit intent intended for system app due to Implicit intent hijacking. This could lead to local e | Sep 4, 2025 | 7.8 | 24 | NO | NO |
CVE-2023-47889HIGH The Android application BINHDRM26 com.bdrm.superreboot 1.0.3, exposes several critical actions through its exported broadcast receivers. These exposed actions can allow any app on | Feb 6, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-44122HIGH The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpa | Sep 27, 2023 | 7.8 | 22 | NO | NO |
CVE-2022-36830MEDIUM PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent | Aug 5, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-36829MEDIUM PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent. | Aug 5, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-33734MEDIUM Sensitive information exposure in onCharacteristicChanged in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission. | Aug 5, 2022 | 5.5 | 19 | NO | NO |
CVE-2024-3108MEDIUM
An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without aut | May 3, 2024 | 5.5 | 17 | NO | NO |
CVE-2023-44127MEDIUM he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps install | Sep 27, 2023 | 5.5 | 17 | NO | NO |
CVE-2023-31014MEDIUM NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on the same device can process the implicit intent meant for t | Sep 20, 2023 | 4.8 | 17 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.