Inure Task Hijacking Vulnerability in Android Applications Prior to Version 11

Vulnerability

A task hijacking vulnerability has been identified in the Inure application by hamza417, affecting all Android versions prior to 11. The issue arises from a misconfiguration in the AndroidManifest.xml file, where the taskAffinity attribute is improperly set. This flaw allows malicious applications to inherit permissions from the vulnerable Inure app, potentially leading to the interception and theft of sensitive information from users' devices.

Impact

Exploitation of this vulnerability allows for task hijacking, where a malicious app can intercept and manipulate tasks of the legitimate Inure app, leading to unauthorized access and theft of sensitive information.

Reproduction

To reproduce this vulnerability, install the malicious application that exploits the task hijacking flaw. Once the malicious app is running, open the legitimate Inure app. The malicious app will intercept the Inure app's tasks and permissions, allowing it to access sensitive information.

Remediation

The vulnerability has been fixed in Inure build 97. Users should update to this version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.8
remediation
8.3
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.