Improper Export Vulnerability in Webull Investing & Trading App for Android
CVE-2025-10721

4.8MEDIUM

Key Information:

Vendor

Webull

Vendor
CVE Published:
19 September 2025

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2025-10721?

A vulnerability found in the Webull Investing & Trading App version 11.2.5.63 for Android arises from improper export specifications in the AndroidManifest.xml file. This flaw enables local attackers to exploit the application's components, potentially leading to unauthorized access or manipulation. The issue was publicly disclosed, and although the vendor was informed early about the threat, no response was received. The vulnerability could affect users who have the app installed on their devices, making it crucial for users to remain vigilant.

Affected Version(s)

Investing & Trading App 11.2.5.63

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

fxizenta (VulDB User)
.
CVE-2025-10721 : Improper Export Vulnerability in Webull Investing & Trading App for Android