Junglewise Threat Intelligence

CVE-2025-65835: Cordova SocialSharing plugin exported broadcast receiver DoS

CVE-2025-65835 · Severity: medium · CVSS 6.2 · Published 2025-12-15

Technologies: Google Android. Vendors: Google, Apache.

Executive brief

The Cordova Social Sharing plugin, used by mobile apps to add native sharing functionality, registers an exported Android broadcast receiver that improperly handles incoming intents. A malicious app on the same device can send crafted broadcasts to crash any application using this plugin, causing repeated service disruptions without requiring special permissions or user interaction.

Technical details

The vulnerability is a null pointer dereference in the exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent. The receiver listens for android.intent.action.SEND intents and accesses Intent.EXTRA_CHOSEN_COMPONENT without null checking. Because the receiver is exported and performs no caller validation, any local application can send malformed ACTION_SEND broadcasts missing the required extra field, triggering a NullPointerException that crashes the host application. This is a local denial-of-service requiring only local network/device access and no authentication. No patch availability information is provided in the advisory.

Affected products

  • Apache Cordova 6.0.4

Timeline

  • 2025-12-15: disclosed: CVE-2025-65835 published on NVD

References

Related threats