CVE-2014-8889: Dropbox SDK

Medium severity, CVSS 5.3. EPSS: 5.8% chance of exploitation in the next 30 days.

Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.

Affected products

  • Dropbox Dropbox SDK: version 1.5.4 only; version 1.6.1 only

Published 2017-09-26. Last modified 2026-06-17.