Improper Export Vulnerability in Ooma Office Business Phone App for Android
CVE-2025-10718
Key Information:
- Vendor
Ooma
- Vendor
- CVE Published:
- 19 September 2025
Badges
What is CVE-2025-10718?
A vulnerability exists in the Ooma Office Business Phone App for Android, specifically affecting the com.ooma.office2 component in version 7.2.2. The flaw allows for the improper export of Android application components, which can lead to unauthorized access and potentially harmful interactions with other applications. The vulnerability can be exploited locally and has been publicly disclosed. Despite efforts to inform the vendor prior to the release, no response was received, raising concerns about user security and the urgency of applying patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Office Business Phone App 7.2.0
Office Business Phone App 7.2.1
Office Business Phone App 7.2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
