CWE-925 · 19 records
Improper Verification of Intent by Broadcast Receiver
CVEs in this class
19 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2024-10576No exploit | Unauthorized factory reset of Infinix devicesinfinix mobile · com.transsion.agingfunction · CWE-925 | Critical9.4 | — | 0.2% | Dec 4, 2024 |
30Monitor | CVE-2023-42543No exploit | Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbsamsung · bixby voice · CWE-925 | High7.5 | — | 0.5% | Nov 7, 2023 |
27Monitor | CVE-2026-20988No exploit | Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary samsung · android · CWE-925 | Medium6.8 | — | 0.1% | Mar 16, 2026 |
22Monitor | CVE-2024-20870No exploit | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to writsamsung · galaxy store · CWE-925 | Medium5.5 | — | 0.1% | May 7, 2024 |
22Monitor | CVE-2025-20951No exploit | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to writsamsung · galaxy store · CWE-925 | Medium5.5 | — | 0.1% | Apr 8, 2025 |
22Monitor | CVE-2025-20972No exploit | Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flosamsung · flow · CWE-925 | Medium5.5 | — | 0.1% | May 7, 2025 |
22Monitor | CVE-2023-44126No exploit | Call management - Implicit intents disclose telephony data such as phone numbers, call states, contactslg · v60 thin q 5g · CWE-925 | Medium5.5 | — | 0.1% | Sep 27, 2023 |
21Monitor | CVE-2026-33173No exploit | Rails Active Storage has possible content type bypass via metadata in direct uploadsrubyonrails · rails · CWE-925 | Medium5.3 | — | 0.4% | Mar 23, 2026 |
21Monitor | CVE-2024-34601No exploit | Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launcsamsung · galaxy store · CWE-925 | Medium5.3 | — | 0.1% | Jul 2, 2024 |
20Monitor | CVE-2024-20853No exploit | Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attackers to write arbitrarsamsung · galaxy themes · CWE-925 | Medium5.1 | — | 0.2% | Apr 1, 2024 |
20Monitor | CVE-2026-21106No exploit | Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable ensamsung mobile · samsung cloud assistant · CWE-925 | Medium5.1 | — | 0.1% | Sep 9, 2026 |
17Monitor | CVE-2025-20942No exploit | Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAIsamsung · android · CWE-925 | Medium4.4 | — | 0.1% | Apr 8, 2025 |
17Monitor | CVE-2025-20958No exploit | Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWsamsung · android · CWE-925 | Medium4.4 | — | 0.1% | May 7, 2025 |
17Monitor | CVE-2025-21027No exploit | Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disamsung · android · CWE-925 | Medium4.4 | — | 0.1% | Sep 3, 2025 |
13Monitor | CVE-2024-20852No exploit | Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to accesamsung · smartthings · CWE-925 | Low3.3 | — | 0.1% | Apr 1, 2024 |
13Monitor | CVE-2024-34600No exploit | Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copysamsung · flow · CWE-925 | Low3.3 | — | 0.1% | Jul 2, 2024 |
13Monitor | CVE-2025-21040No exploit | Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerarsamsung · sassistant · CWE-925 | Low3.3 | — | 0.1% | Sep 3, 2025 |
13Monitor | CVE-2025-21038No exploit | Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modifsamsung · sassistant · CWE-925 | Low3.3 | — | 0.1% | Sep 3, 2025 |
13Monitor | CVE-2025-21039No exploit | Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modifysamsung · sassistant · CWE-925 | Low3.3 | — | 0.1% | Sep 3, 2025 |
- CVE-2024-1057637Monitor
Unauthorized factory reset of Infinix devices
CriticalCVSS 9.4No exploitEPSS 0%infinix mobile · com.transsion.agingfunctionDec 4, 2024
- CVE-2023-4254330Monitor
Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arb
HighCVSS 7.5No exploitEPSS 0%samsung · bixby voiceNov 7, 2023
- CVE-2026-2098827Monitor
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary
MediumCVSS 6.8No exploitEPSS 0%samsung · androidMar 16, 2026
- CVE-2024-2087022Monitor
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to writ
MediumCVSS 5.5No exploitEPSS 0%samsung · galaxy storeMay 7, 2024
- CVE-2025-2095122Monitor
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to writ
MediumCVSS 5.5No exploitEPSS 0%samsung · galaxy storeApr 8, 2025
- CVE-2025-2097222Monitor
Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flo
MediumCVSS 5.5No exploitEPSS 0%samsung · flowMay 7, 2025
- CVE-2023-4412622Monitor
Call management - Implicit intents disclose telephony data such as phone numbers, call states, contacts
MediumCVSS 5.5No exploitEPSS 0%lg · v60 thin q 5gSep 27, 2023
- CVE-2026-3317321Monitor
Rails Active Storage has possible content type bypass via metadata in direct uploads
MediumCVSS 5.3No exploitEPSS 0%rubyonrails · railsMar 23, 2026
- CVE-2024-3460121Monitor
Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launc
MediumCVSS 5.3No exploitEPSS 0%samsung · galaxy storeJul 2, 2024
- CVE-2024-2085320Monitor
Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attackers to write arbitrar
MediumCVSS 5.1No exploitEPSS 0%samsung · galaxy themesApr 1, 2024
- CVE-2026-2110620Monitor
Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable en
MediumCVSS 5.1No exploitEPSS 0%samsung mobile · samsung cloud assistantSep 9, 2026
- CVE-2025-2094217Monitor
Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAI
MediumCVSS 4.4No exploitEPSS 0%samsung · androidApr 8, 2025
- CVE-2025-2095817Monitor
Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoW
MediumCVSS 4.4No exploitEPSS 0%samsung · androidMay 7, 2025
- CVE-2025-2102717Monitor
Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily di
MediumCVSS 4.4No exploitEPSS 0%samsung · androidSep 3, 2025
- CVE-2024-2085213Monitor
Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to acce
LowCVSS 3.3No exploitEPSS 0%samsung · smartthingsApr 1, 2024
- CVE-2024-3460013Monitor
Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copy
LowCVSS 3.3No exploitEPSS 0%samsung · flowJul 2, 2024
- CVE-2025-2104013Monitor
Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerar
LowCVSS 3.3No exploitEPSS 0%samsung · sassistantSep 3, 2025
- CVE-2025-2103813Monitor
Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modif
LowCVSS 3.3No exploitEPSS 0%samsung · sassistantSep 3, 2025
- CVE-2025-2103913Monitor
Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify
LowCVSS 3.3No exploitEPSS 0%samsung · sassistantSep 3, 2025