CVE-2025-15464

Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.
Configurations

No configuration.

History

08 Jan 2026, 23:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2026/Jan/12 -

08 Jan 2026, 22:16

Type Values Removed Values Added
References
  • () https://korelogic.com/Resources/Advisories/KL-001-2026-001.poc.js.txt -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

08 Jan 2026, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-08 21:15

Updated : 2026-01-13 14:03


NVD link : CVE-2025-15464

Mitre link : CVE-2025-15464

CVE.ORG link : CVE-2025-15464


JSON object : View

Products Affected

No product.

CWE
CWE-926

Improper Export of Android Application Components