CVE-2025-9673

MEDIUM

Kakao Hey Kakao App <2.17.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.kakao.i.connect. The manipulation results in improper export of android application components. The attack requires a local approach. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Scores

CVSS v3 5.3
EPSS 0.0002
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-926
Status published
Products (5)
Kakao/헤이카카오 Hey Kakao App 2.17.0
Kakao/헤이카카오 Hey Kakao App 2.17.1
Kakao/헤이카카오 Hey Kakao App 2.17.2
Kakao/헤이카카오 Hey Kakao App 2.17.3
Kakao/헤이카카오 Hey Kakao App 2.17.4
Published Aug 29, 2025
Tracked Since Feb 18, 2026