Improper Export of Android Application Components in Euro Information CIC App
CVE-2025-9097

5.3MEDIUM

Key Information:

Vendor
CVE Published:
18 August 2025

What is CVE-2025-9097?

A vulnerability exists in the Euro Information CIC banque et compte en ligne App version 12.56.0 for Android. This vulnerability arises from an unknown functionality within the AndroidManifest.xml file of the component com.cic_prod.bad, which results in the improper export of application components. This security flaw can be exploited by manipulating application exports, potentially allowing various attacks initiated locally. Despite early notifications made to the vendor regarding this vulnerability disclosure, there has been no response.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-9097 : Improper Export of Android Application Components in Euro Information CIC App