CVE-2025-15464High· 7.5▾ TwilightExported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.
fun_print = 6.05.15Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-10718Medium· 5.3A vulnerability was found in Ooma Office Business Phone App up to 7.2.2 on Android
CVE-2025-10722Medium· 5.3A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android
CVE-2026-68928High· 8.6Acode is a powerful text and code editor for Android
CVE-2026-12960Medium· 6.0An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent that causes ASUS Router App to open an specified URL. Refer to the ' Secur…
CVE-2026-86701Low· 2.5Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components
CVE-2026-81301High· 8.5Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps the caller-controlled URI path directly to a filesystem path and…