Junglewise Threat Intelligence

CVE-2026-30283: PEAKSEL Animal Sounds and Ringtones arbitrary file overwrite

CVE-2026-30283 · Severity: critical · CVSS 9.8 · Published 2026-03-31

Executive brief

A critical security flaw has been identified in the Animal Sounds and Ringtones mobile application. The app fails to properly verify files during the import process, which could allow a malicious actor to overwrite internal application files. This could lead to the app being disabled, the theft of sensitive user information, or the execution of unauthorized commands on the device.

Technical details

A path traversal vulnerability (CWE-22) exists in the 'com.bra.classes.ExternalProcessorActivity' component of the Animal Sounds and Ringtones Android application. The flaw stems from insufficient validation of filenames and content during the file import process. An attacker can provide a specially crafted file that uses path traversal sequences to escape the intended directory and overwrite sensitive internal configuration or executable files. Successful exploitation can lead to arbitrary code execution, persistent denial of service, or unauthorized access to the app's internal data. The attack can be triggered automatically when a victim interacts with a malicious application designed to interface with the vulnerable component.

Affected products

  • PEAKSEL D.O.O. NIS Animal Sounds and Ringtones 1.3.0

Timeline

  • 2026-03-31: disclosed: Vulnerability disclosed by Secsys-FDU/Fudan University researchers.
  • 2026-03-31: advisory: CVE-2026-30283 published.

References