References https://nvd.nist.gov/vuln/detail/CVE-2025-21016 https://github.com/advisories/GHSA-499c-pwhc-q8hp https://devhub.checkmarx.com/cve-details/cve-2025-21016/ https://dbugs.ptsecurity.com/vulnerability/PT-2025-32107 https://avd.aquasec.com/nvd/2025/cve-2025-21016/ https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=04 https://cve.imfht.com/detail/CVE-2025-21016 https://www.nsfocus.net/vulndb/130962 https://radar.offseq.com/threat/cve-2025-21016-cwe-284-improper-access-control-in--cd52b4e1
Related Vulnerabilities(CVE-2025-0087) Android UninstallerActivity onCreate 方法权限漏洞 权限管理错误(CVE-2025-8745)Weee RICEPO Android应用组件不当导出漏洞金和OA C6 /c6/jhsoft.mobileapp/AndroidSevices/HomeService.asmx/GetHomeInfo SQL 注入漏洞(CVE-2025-21024) Smart View在Android 16之前版本中因使用隐式意图导致敏感信息泄露漏洞PoCandroid-minsdk-21: AndroidManifest.xml minSdkVersion Set to 21 (Insecure Minimum SDK Version)PoCandroid-user-certificates-trust: Android Trusts User CertificatesPoCimproper-certificate-validation: Android Improper Certificate Validation - DetectPoCandroid-debug-enabled: Android Debug EnabledPoCinsecure-provider-path: Android Insecure Provider Path - DetectPoCwebview-universal-access: Android WebView Universal Access - DetectPoCandroid-debug-database-exposed: Android Debug ManagerPoCexposed-adb: Exposed Android Debug Bridge