A security vulnerability has been detected in BuzzFeed App 2024.9 on Android. This affects an unknown part of the file AndroidManifest.xml of the component com.buzzfeed.android. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
History

Thu, 11 Sep 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Buzzfeed
Buzzfeed buzzfeed
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:buzzfeed:buzzfeed:2024.9:*:*:*:*:android:*:*
Vendors & Products Buzzfeed
Buzzfeed buzzfeed

Mon, 18 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 17 Aug 2025 22:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in BuzzFeed App 2024.9 on Android. This affects an unknown part of the file AndroidManifest.xml of the component com.buzzfeed.android. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Title BuzzFeed App com.buzzfeed.android AndroidManifest.xml improper export of android application components
Weaknesses CWE-926
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-08-18T13:13:48.756Z

Reserved: 2025-08-17T12:36:56.626Z

Link: CVE-2025-9093

cve-icon Vulnrichment

Updated: 2025-08-18T13:12:56.653Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-17T22:15:25.897

Modified: 2025-09-11T17:46:25.760

Link: CVE-2025-9093

cve-icon Redhat

No data.