Apktool is a reverse-engineering and repackaging utility for Android application packages, used primarily by researchers, developers, and security professionals for analyzing APK structure and contents. Its modest vulnerability history centers on path-traversal weaknesses that arise during archive extraction and file handling, a structural concern for any tool operating on untrusted binary inputs. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apktool over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-21633HIGH Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to their resource names which can be | Jan 3, 2024 | 7.8 | 36 | NO | YES |
CVE-2026-39973HIGH Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability in `brut/androlib/res/decoder/ResFileDecoder.java` allows a | Apr 21, 2026 | 7.1 | 26 | NO | NO |
CVE-2024-24482CRITICAL Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal. | Feb 2, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apktool.
Media articles that mention a CVE ID that affects a product developed by Apktool — matched by CVE ID, not by vendor name.