PT-2025-38407 · Realme+1 · Realme Backuprestore+1
Brucewebva
·
Published
2025-09-18
·
Updated
2025-09-19
·
CVE-2025-57452
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
realme BackupRestore app version 15.1.12 2810c08 250314
Description
The application suffers from improper URI scheme handling within the
com.coloros.pc.PcToolMainActivity component. This allows local attackers to cause a crash and potential cross-site scripting (XSS) through crafted Android Debug Bridge (ADB) intents.Recommendations
Update to a newer version of the application that addresses this issue. As a temporary workaround, restrict the use of ADB intents with the application.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coloros
Realme Backuprestore