Intel

AIKIDO-2025-10637

react-native-exponea-sdk is vulnerable to Improper Export of Android Application Components

Improper Export of Android Application Components Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 11, 2025

60

Medium Risk

This Affects:

JSreact-native-exponea-sdk
0.0.1 - 2.2.0
Fixed in 2.3.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package set the android:exported attribute to true for certain components in the AndroidManifest.xml file. This setting allows those components (such as activities, services, or broadcast receivers) to be invoked by external applications. If not properly restricted, this configuration can increase the risk of unauthorized access, privilege escalation, or unintended data exposure.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

react-native-exponea-sdk is vulnerable to Improper Export of Android Application Components in versions 0.0.1 - 2.2.0.

How to fix this

Upgrade the react-native-exponea-sdk library to the patch version.