A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.thinkyeah.galleryvault. The manipulation leads to improper export of android application components. The attack can only be performed from a local environment. The exploit is publicly available and might be used.
History

Wed, 10 Sep 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Galleryvault
Galleryvault gallery Vault
Google
Google android
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:galleryvault:gallery_vault:*:*:*:*:*:android:*:*
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
Vendors & Products Galleryvault
Galleryvault gallery Vault
Google
Google android

Tue, 02 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 30 Aug 2025 15:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.thinkyeah.galleryvault. The manipulation leads to improper export of android application components. The attack can only be performed from a local environment. The exploit is publicly available and might be used.
Title GalleryVault Gallery Vault App com.thinkyeah.galleryvault AndroidManifest.xml improper export of android application components
Weaknesses CWE-926
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-09-02T15:17:25.863Z

Reserved: 2025-08-29T11:27:56.710Z

Link: CVE-2025-9695

cve-icon Vulnrichment

Updated: 2025-09-02T14:47:38.598Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-30T16:15:37.663

Modified: 2025-09-10T12:54:03.540

Link: CVE-2025-9695

cve-icon Redhat

No data.