CVE-2025-9134
A security vulnerability has been detected in AfterShip Package Tracker App up to 5.24.1 on Android.
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
A security vulnerability has been detected in AfterShip Package Tracker App up to 5.24.1 on Android. The affected element is an unknown function of the file AndroidManifest.xml of the component com.aftership.AfterShip. The manipulation leads to improper export of android application components. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and replied: "After reviewing your report, we have confirmed that this vulnerability does indeed exist and we are actively working to fix it."
- CVSS 4.0
- 1.9 LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-926
- Affected
- aftership/aftership package tracker
- Source
- cna@vuldb.com
References
- https://github.com/KMov-g/androidapps/blob/main/com.aftership.AfterShip.mdExploit, Third Party Advisory
- https://github.com/KMov-g/androidapps/blob/main/com.aftership.AfterShip.md#steps-to-reproduceExploit, Third Party Advisory
- https://vuldb.com/?ctiid.320514Permissions Required, VDB Entry
- https://vuldb.com/?id.320514Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.615253Third Party Advisory, VDB Entry
- https://github.com/KMov-g/androidapps/blob/main/com.aftership.AfterShip.mdExploit, Third Party Advisory
- https://github.com/KMov-g/androidapps/blob/main/com.aftership.AfterShip.md#steps-to-reproduceExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.