Executive brief
The Cordova Social Sharing plugin, used by mobile apps to add native sharing functionality, registers an exported Android broadcast receiver that improperly handles incoming intents. A malicious app on the same device can send crafted broadcasts to crash any application using this plugin, causing repeated service disruptions without requiring special permissions or user interaction.
Technical details
The vulnerability is a null pointer dereference in the exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent. The receiver listens for android.intent.action.SEND intents and accesses Intent.EXTRA_CHOSEN_COMPONENT without null checking. Because the receiver is exported and performs no caller validation, any local application can send malformed ACTION_SEND broadcasts missing the required extra field, triggering a NullPointerException that crashes the host application. This is a local denial-of-service requiring only local network/device access and no authentication. No patch availability information is provided in the advisory.
Affected products
- Apache Cordova 6.0.4
Timeline
- 2025-12-15: disclosed: CVE-2025-65835 published on NVD