Improper Export Vulnerability in Webull Investing & Trading App for Android
CVE-2025-10721
Key Information:
- Vendor
Webull
- Status
- Vendor
- CVE Published:
- 19 September 2025
Badges
What is CVE-2025-10721?
A vulnerability found in the Webull Investing & Trading App version 11.2.5.63 for Android arises from improper export specifications in the AndroidManifest.xml file. This flaw enables local attackers to exploit the application's components, potentially leading to unauthorized access or manipulation. The issue was publicly disclosed, and although the vendor was informed early about the threat, no response was received. The vulnerability could affect users who have the app installed on their devices, making it crucial for users to remain vigilant.
Affected Version(s)
Investing & Trading App 11.2.5.63
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved