CVE-2025-63434
The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downloads and extracts update packages containing executable code without performing a cryptographic integrity or authenticity check on their contents. An attacker who can control the update metadata can serve a malicious package, which the application will accept, extract, and later execute, leading to arbitrary code execution.
Vendor
Product
CWE
Yayın Tarihi
2025-11-24 17:16:08
Güncelleme
2025-11-28 17:06:23
Source Identifier
cve@mitre.org
KEV Date Added
-