Junglewise Threat Intelligence

CVE-2025-50861: Lotus Cars Android app improper access control in PushDeepLinkActivity

CVE-2025-50861 · Severity: medium · CVSS 6.5 · Published 2025-08-14

Executive brief

The Lotus Cars Android application contains a security flaw where a specific internal component is improperly exposed. This allows other malicious apps on the same device, or an attacker with physical access via a computer, to bypass security checks and interact with the app's internal functions. This could lead to unauthorized access to app features, service disruptions, or manipulation of the app's logic.

Technical details

The vulnerability is classified as Improper Access Control (CWE-284) due to an improperly exported Android component. Specifically, the 'PushDeepLinkActivity' in the AndroidManifest.xml is set as exported without requiring appropriate permissions or authentication. An attacker can exploit this by sending an intent via a malicious application installed on the same device or through the Android Debug Bridge (ADB). Successful exploitation allows the attacker to invoke internal application functionality, which may lead to logic abuse or a denial of service (DoS) condition within the app.

Affected products

  • Lotus Cars Lotus Cars Android app 1.2.8

Timeline

  • 2025-05: disclosed: Reported to vendor
  • 2025-08-14: advisory: NVD publication date

References

Related threats