CVE-2025-15385: Tecno Boomplay

Critical severity, CVSS 9.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects com.Afmobi.Boomplayer: 7.4.63.

Affected products

  • Tecno Boomplay: up to and including 7.4.63

Published 2026-01-06. Last modified 2026-10-07.