Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Jan 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eddyverbruggen
Eddyverbruggen cordova Social Sharing |
|
| CPEs | cpe:2.3:a:eddyverbruggen:cordova_social_sharing:6.0.4:*:*:*:*:node.js:*:* cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Eddyverbruggen
Eddyverbruggen cordova Social Sharing |
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cordova
Cordova plugin-x-socialsharing Google android |
|
| Vendors & Products |
Cordova
Cordova plugin-x-socialsharing Google android |
Mon, 15 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-476 | |
| Metrics |
cvssV3_1
|
Mon, 15 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses Intent.EXTRA_CHOSEN_COMPONENT without checking for null. If a broadcast is sent with extras present but without EXTRA_CHOSEN_COMPONENT, the code dereferences a null value and throws a NullPointerException. Because the receiver is exported and performs no permission or caller validation, any local application on the device can send crafted ACTION_SEND broadcasts to this component and repeatedly crash the host application, resulting in a local, unauthenticated application-level denial of service for any app that includes the plugin. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-15T19:31:22.320Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65835
Updated: 2025-12-15T19:30:25.776Z
Status : Analyzed
Published: 2025-12-15T19:16:05.373
Modified: 2026-01-07T20:57:22.673
Link: CVE-2025-65835
No data.
OpenCVE Enrichment
Updated: 2025-12-16T17:11:16Z