Vulnerability Description
A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.thinkyeah.galleryvault. The manipulation leads to improper export of android application components. The attack can only be performed from a local environment. The exploit is publicly available and might be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Galleryvault | Gallery Vault | <= 4.5.2 |
| Android | < 11.0 |
Related Weaknesses (CWE)
References
- https://github.com/KMov-g/androidapps/blob/main/com.thinkyeah.galleryvault.mdExploitThird Party Advisory
- https://github.com/KMov-g/androidapps/blob/main/com.thinkyeah.galleryvault.md#stExploitThird Party Advisory
- https://vuldb.com/?ctiid.321906Permissions RequiredVDB Entry
- https://vuldb.com/?id.321906Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.639039Third Party AdvisoryVDB Entry
- https://github.com/KMov-g/androidapps/blob/main/com.thinkyeah.galleryvault.mdExploitThird Party Advisory
- https://github.com/KMov-g/androidapps/blob/main/com.thinkyeah.galleryvault.md#stExploitThird Party Advisory
FAQ
What is CVE-2025-9695?
CVE-2025-9695 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.think...
How severe is CVE-2025-9695?
CVE-2025-9695 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-9695?
Check the references section above for vendor advisories and patch information. Affected products include: Galleryvault Gallery Vault, Google Android.