CVE-2025-65835

⚪ Do wiadomości

Błąd w pluginie cordova-plugin-x-socialsharing na Androidzie umożliwia atak DoS przez lokalne aplikacje.

CVSS
6.2
EPSS
0.3%
Exploit
poc
Vendor
eddyverbruggen
Opis źródłowy (NVD)

The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses Intent.EXTRA_CHOSEN_COMPONENT without checking for null. If a broadcast is sent with extras present but without EXTRA_CHOSEN_COMPONENT, the code dereferences a null value and throws a NullPointerException. Because the receiver is exported and performs no permission or caller validation, any local application on the device can send crafted ACTION_SEND broadcasts to this component and repeatedly crash the host application, resulting in a local, unauthenticated application-level denial of service for any app that includes the plugin.

dos exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.2
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-12-15 19:16:05 UTC
Ostatnia modyfikacja (NVD)2026-09-15 20:17:58 UTC
Referencje