PT-2025-33718 · Aftership · Aftership Package Tracker App

·

CVE-2025-9134

·

Published

2025-08-19

·

Updated

2025-09-12

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: AfterShip Package Tracker App versions through 5.24.1
Description: A security vulnerability has been detected in AfterShip Package Tracker App on Android. The affected element is an unknown function within the AndroidManifest.xml file of the com.aftership.AfterShip component. This manipulation results in the improper export of Android application components. The attack requires local execution. The exploit has been publicly disclosed and may be utilized. The vendor has acknowledged the vulnerability and is actively working on a fix.
Recommendations: AfterShip Package Tracker App versions through 5.24.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9134

Affected Products

Aftership Package Tracker App