CVE-2025-7940 Details
Description
A vulnerability was found in Genshin Albedo Cat House App 1.0.2 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.house.auscat. The manipulation leads to improper export of android application components. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
A task hijacking vulnerability has been identified in the Genshin Albedo Cat House App version 1.0.2 for Android. This issue arises from a misconfiguration in the AndroidManifest.xml file of the component com.house.auscat, leading to improper export of application components. As a result, malicious apps can inherit permissions from vulnerable ones, potentially allowing for phishing attacks to steal login credentials. This vulnerability affects all Android versions prior to Android 11, and requires local access to exploit.
To mitigate this vulnerability, developers should set the taskAffinity property of application activities in the AndroidManifest.xml file. This can be done by assigning a value that forces activities to use a randomly generated task affinity, or by setting a specific value at the application tag to apply to all activities.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 21, 2025CISA-ADP
Assessed Jul 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/KMov-g/androidapps/blob/main/com.house.auscat.md | [email protected] | ExploitTechnical Description |
| https://github.com/KMov-g/androidapps/blob/main/com.house.auscat.md#video-proof-of-concept | [email protected] | ExploitTechnical Description |
| https://vuldb.com/?ctiid.317077 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.317077 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.619036 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-926 | Improper Export of Android Application Components | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Genshin Albedo Cat House App | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jul 21, 2025 | New CVE Received | [email protected] |
Volerion