CVE-2026-13514Low· 2.4▾ SunlitA weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.chess. This manipulation causes exposure of backup file t…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
0.1% → 0.2%
A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.chess. This manipulation causes exposure of backup file to an unauthorized control sphere. It is feasible to perform the attack on the physical device. The exploit has been made available to the public and could be used for attacks. Upgrading the affected component is advised. The vendor was informed early about this issue. They confirmed the existence and that they will address it. Furthermore, they explain that their bug bounty "explicitly excludes physical-access attacks". However, they appreciate the quality of the report and aim at making a goodwill payment to the researcher.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42902High· 7.8Microsoft PowerToys Elevation of Privilege Vulnerability
CVE-2026-45490High· 7.8.NET SDK Elevation of Privilege Vulnerability
CVE-2026-47298High· 8.0Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-48579Critical· 9.1Microsoft Exchange Online Information Disclosure Vulnerability
CVE-2026-16346Critical· 9.9IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-25254Critical· 9.8Improper authorization leads to Remote Code Execution via SocketIO interface.