CWE-925 3 CVEs MITRE definition ↗

CWE-925: Improper Verification of Intent by Broadcast Receiver

Overview

CWE-925 (Improper Verification of Intent by Broadcast Receiver) documents a weakness type used across vulnerability databases and security assessments. Use the sections below for definition, context, and mapped CVEs.

Security impact
Security impact: Depends on product and context; use CVE records, severity scores, and MITRE guidance to prioritize.

Description

The Android application uses a Broadcast Receiver that receives an Intent but does not properly verify that the Intent came from an authorized source.

Applicable platforms

Kind Name Class Prevalence OS / CPE
language Not Language-Specific Undetermined
technology Mobile Undetermined

Related CVEs in this database

These CVEs are mapped to this weakness in this database and kept for traceability and search.

CVE Published Summary
CVE-2026-33173 2026-03-23 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary metadata from the client…
CVE-2024-10576 2024-12-04 Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to perf…
CVE-2023-44126 2023-09-27 The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installe…

Content submission

Name
CWE Content Team
Organization
MITRE
Date
2013-06-24
Version
2.5

Content modifications

Date Name Version Importance Comment
2014-02-18 CWE Content Team 2.6 updated Alternate_Terms, Demonstrative_Examples, Description, References
2017-11-08 CWE Content Team 3.0 updated Demonstrative_Examples
2019-01-03 CWE Content Team 3.2 updated Related_Attack_Patterns
2020-02-24 CWE Content Team 4.0 updated Applicable_Platforms, Relationships
2022-10-13 CWE Content Team 4.9 updated Relationships
2023-04-27 CWE Content Team 4.11 updated Detection_Factors, Relationships
2023-06-29 CWE Content Team 4.12 updated Mapping_Notes
2025-12-11 CWE Content Team 4.19 updated Weakness_Ordinalities
2026-04-30 CWE Content Team 4.20 updated Observed_Examples
cvelogic Threat Intelligence