CVE-2025-9673: Kakao 헤이카카오 Hey Kakao App com.kakao.i.connect AndroidManifest.xml improper export of android application components
A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.kakao.i.connect. The manipulation results in improper export of android application components. The attack requires a local approach. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9673?
CVE-2025-9673 has not been assigned a CVSS score yet, but it is critical to address due to the potential for improper export of application components.
How do I fix CVE-2025-9673?
To fix CVE-2025-9673, update the Kakao Hey Kakao App to the latest version beyond 2.17.4.
What is the affected version for CVE-2025-9673?
CVE-2025-9673 affects Kakao Hey Kakao App versions up to and including 2.17.4.
What component is impacted by CVE-2025-9673?
CVE-2025-9673 impacts the AndroidManifest.xml file of the component com.kakao.i.connect.
What kind of vulnerability is CVE-2025-9673?
CVE-2025-9673 is a vulnerability related to improper export of Android application components.