VulnerAlert



ANDROID
GOOGLE
27-10-2025 09:57

CVE-2025-12080 Vulnerabilidad documentada

Sin puntuación
Tags
#google
#android
#exploit
#source
#form
#config
#vulnerability
#application
#arbitrary
#compromise
#configuration
#allow
#attack
#unauthorized
Descripción
On Wear OS devices, when Google Messages is configured as the default SMS/MMS/RCS application, handling of ACTION_SENDTO intents utilizing sms:, smsto:, mms:, and mmsto: Uniform Resource Identifier (URI) schemes incorrectly implemented. Due to this misconfiguration, an attacker capable invoking Android intent can exploit vulnerability send messages on user’s behalf arbitrary receivers without requiring any further user interaction or specific permissions. This allows for silent unauthorized transmission from a compromised device.
https://towerofhanoi.it/writeups/cve-2025-12080/
Referencia
CVE-2025-12080
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2025-12080
Resultados similares
Coincidentes en almenos en 50% de los tags
28-10-2025
Chrome Zero-Day Exploited to Deliver Italian Memento Labs\' LeetAgent Spyware The zero-day ex...
Ver información
27-10-2025 CVE-2025-61482
Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 ...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por