CVE-2025-25758: Kukufm
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml
Affected products
- Kukufm Kukufm: version 1.12.7 only
Published 2025-03-20. Last modified 2026-06-17.