Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 07 Jan 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eddyverbruggen
Eddyverbruggen cordova Social Sharing |
|
| CPEs | cpe:2.3:a:eddyverbruggen:cordova_social_sharing:6.0.4:*:*:*:*:node.js:*:* cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Eddyverbruggen
Eddyverbruggen cordova Social Sharing |
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cordova
Cordova plugin-x-socialsharing Google android |
|
| Vendors & Products |
Cordova
Cordova plugin-x-socialsharing Google android |
Mon, 15 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-476 | |
| Metrics |
cvssV3_1
|
Mon, 15 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses Intent.EXTRA_CHOSEN_COMPONENT without checking for null. If a broadcast is sent with extras present but without EXTRA_CHOSEN_COMPONENT, the code dereferences a null value and throws a NullPointerException. Because the receiver is exported and performs no permission or caller validation, any local application on the device can send crafted ACTION_SEND broadcasts to this component and repeatedly crash the host application, resulting in a local, unauthenticated application-level denial of service for any app that includes the plugin. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-15T19:31:22.320Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65835
Updated: 2025-12-15T19:30:25.776Z
Status : Analyzed
Published: 2025-12-15T19:16:05.373
Modified: 2026-01-07T20:57:22.673
Link: CVE-2025-65835
No data.
OpenCVE Enrichment
Updated: 2025-12-16T17:11:16Z