PT-2021-19862 · Nextcloud · Nextcloud Android App

·

CVE-2021-32695

·

Published

2021-06-17

·

Updated

2026-07-12

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Android app versions prior to 3.16.1
Description The Nextcloud Android app is vulnerable to an issue where a malicious app on the same device could access the shared preferences of the Nextcloud Android application. This requires user-interaction, as the victim must initiate the sharing flow and choose the malicious app. The shared preferences contain limited private data, such as push tokens and the account name.
Recommendations For versions prior to 3.16.1, update to version 3.16.1 to resolve the issue. As a temporary workaround, consider restricting the sharing flow to trusted apps until the update is applied.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-NEXTCLOUD-2021-32695
CVE-2021-32695
GHSA-25M9-CF6C-QF2C

Affected Products

Nextcloud Android App