CVE-2025-63434 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages contai…
High CVSS: 8.8

CVE-2025-63434

The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution.
Vendor
Xtooltech
Product
Xtool Anyscan
CWE
CWE-494
Yayın Tarihi
2025-11-24 17:16:08
Güncelleme
2025-11-28 17:06:23
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar