Dunamu StockPlus App Improper Export of Android Application Components Vulnerability

Vulnerability

A vulnerability allowing task hijacking has been identified in the Dunamu StockPlus App for Android, in versions through 7.62.10. This issue arises from an improper export of application components, specifically within the AndroidManifest.xml file of the com.dunamu.stockplus component. The vulnerability allows malicious apps to inherit permissions from vulnerable apps, potentially leading to phishing attacks by manipulating or taking over tasks on the device.

Impact

Exploitation of this vulnerability allows for task hijacking, where a malicious app can take over tasks of the vulnerable app, inheriting its permissions. This could be used to phish for login credentials or manipulate the user in other ways.

Reproduction

The vulnerability can be reproduced by creating a malicious app that targets the Dunamu StockPlus App. This malicious app can then inherit permissions from the vulnerable app, allowing it to access sensitive data or perform actions on behalf of the user. This exploitation can be automated with a public proof-of-concept exploit available on GitHub.

Added: Jul 20, 2025, 1:23 PM
Updated: Jul 20, 2025, 1:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
4.6
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.