CWE-927Variant

Use of Implicit Intent for Sensitive Communication

Incomplete in the CWE catalog · 16 CVEs mapped

16
CVEs mapped
5.0
Median CVSS
What it is

The Android application uses an implicit intent for transmitting sensitive data to other applications.

Recent examples
2.8cvss
CVE-2024-3480

An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data

An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data.

LOWno explanation yet
0%
epss
5.5cvss
CVE-2024-3108

An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of…

An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization. 

MEDIUMno explanation yet
0%
epss
4.4cvss
CVE-2023-41828

An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider

An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider.  

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-927
Abstraction
Variant
Structure
Simple
Status
Incomplete
References (2)