CVE-2025-9674

A flaw has been found in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.hatsune.eagleee. This manipulation causes improper export of android application components. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/KMov-g/androidapps/blob/main/com.hatsune.eagleee.md Exploit Mitigation Third Party Advisory
https://github.com/KMov-g/androidapps/blob/main/com.hatsune.eagleee.md#steps-to-reproduce Exploit Mitigation Third Party Advisory
https://vuldb.com/?ctiid.321884 Permissions Required VDB Entry
https://vuldb.com/?id.321884 Third Party Advisory VDB Entry
https://vuldb.com/?submit.638068 Third Party Advisory VDB Entry
https://github.com/KMov-g/androidapps/blob/main/com.hatsune.eagleee.md Exploit Mitigation Third Party Advisory
https://github.com/KMov-g/androidapps/blob/main/com.hatsune.eagleee.md#steps-to-reproduce Exploit Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:transbyte:scooper_news:*:*:*:*:*:android:*:*
cpe:2.3:o:google:android:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-29 21:15

Updated : 2025-09-08 16:35


NVD link : CVE-2025-9674

Mitre link : CVE-2025-9674

CVE.ORG link : CVE-2025-9674


JSON object : View

Products Affected

transbyte

  • scooper_news

google

  • android
CWE
CWE-926

Improper Export of Android Application Components

NVD-CWE-noinfo