CWE-926Variant

Improper Export of Android Application Components

Incomplete in the CWE catalog · 86 CVEs mapped

86
CVEs mapped
4.8
Median CVSS
What it is

The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.

Recent examples
none
CVE-2026-20516

In MiracastService, there is a possible escalation of privilege due to a confused deputy

In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.

no explanation yet
epss
none
CVE-2026-21081

CVE-2026-21081 - UNKNOWN Severity Vulnerability

Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

no explanation yet
0%
epss
6.1cvss
CVE-2026-21063

CVE-2026-21063 - MEDIUM Severity Vulnerability

Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-926
Abstraction
Variant
Structure
Simple
Status
Incomplete
References (1)