CVE-2025-65835

Source
https://cve.org/CVERecord?id=CVE-2025-65835
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65835.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-65835
Published
2025-12-15T19:16:05.373Z
Modified
2026-01-09T07:59:17.400283Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses Intent.EXTRACHOSENCOMPONENT without checking for null. If a broadcast is sent with extras present but without EXTRACHOSENCOMPONENT, the code dereferences a null value and throws a NullPointerException. Because the receiver is exported and performs no permission or caller validation, any local application on the device can send crafted ACTION_SEND broadcasts to this component and repeatedly crash the host application, resulting in a local, unauthenticated application-level denial of service for any app that includes the plugin.

References

Affected packages

Git / github.com/eddyverbruggen/socialsharing-phonegap-plugin

Affected ranges

Type
GIT
Repo
https://github.com/eddyverbruggen/socialsharing-phonegap-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

4.*
4.3.11
4.3.12
4.3.13
4.3.14
4.3.15
4.3.16
4.3.17
4.3.18
4.3.19
4.3.2
4.3.20
4.3.3
4.3.4
4.3.5
4.3.6
4.3.8
5.*
5.0.0
5.0.1
5.0.10
5.0.11
5.0.12
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.1.6
5.1.7
5.1.8
5.2.0
5.2.1
5.3.0
5.3.1
5.3.2
5.4.0
5.4.4
5.4.5
5.4.6
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.8
6.*
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65835.json"