Command Palette

Search for a command to run...

Bundle Report

im-vector-app v1.6.52

Bundle risk53medium
Binary-only · L1Live analyzer output · not mock dataAnalyzed just now

v1.6.52build 40106524medium· 53

66f8aecb050eff7d81c992c03e2186f66adb752729344ae3e24a98a6b4ab4613

Platform
Android · APK
Bundle size
73.0 MB
OS range
Android API 21 → Android API 35
Architectures
x86_64
Permissions
34

Store review readiness

Expected to pass review

All known pre-review checks pass.

Submit. All known pre-review checks pass. Reviewer may still raise non-static-analysis concerns (screenshots, metadata, UX) — those are out of scope here.

Blocking0

No pre-review rejection causes

None detected
Needs review0

No reviewer-flag items

None detected
OK5

What was checked and passed

  • Data Safety form covers SDK-collected data categories
  • Data Safety form covers third-party sharing
  • 2 bundled SDKs profiled against Google Data Safety
  • No version-confirmed CVEs against bundled SDKs
  • Static surface clusters with labeled-clean corpus neighbors· corpus k-NN bad-neighbor weight 0.00 (low)
90 findings
  • Historical CVE on SDK (build version not detected): Protocol BuffersSDK vulnerability · info

    GHSA-4gg5-vx3j-xwc7 — Protobuf Java vulnerable to Uncontrolled Resource Consumption

    component: protobuf

  • Historical CVE on SDK (build version not detected): Protocol BuffersSDK vulnerability · info

    GHSA-735f-pc8j-v9w8 — protobuf-java has potential Denial of Service issue

    component: protobuf

  • Historical CVE on SDK (build version not detected): Protocol BuffersSDK vulnerability · info

    GHSA-g5ww-5jh7-63cx — Protobuf Java vulnerable to Uncontrolled Resource Consumption

    component: protobuf

  • Historical CVE on SDK (build version not detected): Protocol BuffersSDK vulnerability · info

    GHSA-h4h5-3hr4-j3g2 — protobuf-java has a potential Denial of Service issue

    component: protobuf

  • Historical CVE on SDK (build version not detected): Protocol BuffersSDK vulnerability · info

    GHSA-wrvw-hg22-4m67 — A potential Denial of Service issue in protobuf-java

    component: protobuf

  • Historical CVE on SDK (build version not detected): GsonSDK vulnerability · info

    GHSA-4jrv-ppp4-jm57 — Deserialization of Untrusted Data in Gson

    component: gson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-27xj-rqx5-2255 — jackson-databind mishandles the interaction between serialization gadgets and typing

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-288c-cq4h-88gq — XML External Entity (XXE) Injection in Jackson Databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-3x8x-79m2-3w2w — jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-4gq5-ch57-c2mg — Arbitrary Code Execution in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-4w82-r329-3q67 — Deserialization of Untrusted Data in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-57j2-w4cx-62h2 — Deeply nested json in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-58pp-9c76-5625 — jackson-databind mishandles the interaction between serialization gadgets and typing

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-5949-rw7g-wx7w — Deserialization of untrusted data in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-5p34-5m6p-p58g — jackson-databind mishandles the interaction between serialization gadgets and typing

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-5r5r-6hpj-8gg9 — Serialization gadget exploit in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-5ww9-j83m-q7qx — Information exposure in FasterXML jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-645p-88qh-w398 — Arbitrary Code Execution in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-6fpp-rgj9-8rwc — Deserialization of untrusted data in FasterXML jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-6wqp-v4v6-c87c — Deserialization of Untrusted Data

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-758m-v56v-grj4 — jackson-databind mishandles the interaction between serialization gadgets and typing

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-85cw-hj65-qqv9 — Polymorphic Typing issue in FasterXML jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-89qr-369f-5m5x — Unsafe Deserialization in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-8c4j-34r4-xr8g — Unsafe Deserialization in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-8w26-6f25-cm9x — Unsafe Deserialization in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-95cm-88f5-f2c7 — jackson-databind mishandles the interaction between serialization gadgets and typing

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-9gph-22xh-8x98 — Unsafe Deserialization in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-9m6f-7xcq-8vf8 — Unsafe Deserialization in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-9mxf-g3x6-wv74 — Server-Side Request Forgery (SSRF) in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-9vvp-fxw6-jcxr — jackson-databind mishandles the interaction between serialization gadgets and typing

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-c265-37vj-cwcc — Deserialization of untrusted data in Jackson Databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-c2q3-4qrh-fm48 — Deserialization of untrusted data in Jackson Databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-c8hm-7hpq-7jhg — com.fasterxml.jackson.core:jackson-databind vulnerable to Deserialization of Untrusted Data

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-cf6r-3wgc-h863 — Polymorphic deserialization of malicious object in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-cggj-fvv3-cqwv — FasterXML jackson-databind allows unauthenticated remote code execution

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-cjjf-94ff-43w7 — jackson-databind Deserialization of Untrusted Data vulnerability

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-cmfg-87vq-g5g4 — Deserialization of untrusted data in FasterXML jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-cvm9-fjm9-3572 — Unsafe Deserialization in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-f3j5-rmmp-3fc5 — Improper Input Validation in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-f9hv-mg5h-xcw9 — Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-f9xh-2qgp-cq57 — Unsafe Deserialization in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-fmmc-742q-jg75 — jackson-databind polymorphic typing issue

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-fqwf-pjwf-7vqv — jackson-databind mishandles the interaction between serialization gadgets and typing

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-gjmw-vf9h-g25v — jackson-databind polymorphic typing issue

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-gwp4-hfv6-p7hw — Deserialization of untrusted data in FasterXML jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-gww7-p5w4-wrfv — Deserialization of Untrusted Data in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-h3cw-g4mq-c5x2 — Code Injection in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-h4rc-386g-6m85 — jackson-databind mishandles the interaction between serialization gadgets and typing

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-h592-38cm-4ggp — jackson-databind vulnerable to deserialization flaw leading to unauthenticated remote code execution

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-h822-r4r5-v8jg — Polymorphic Typing issue in FasterXML jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-j823-4qch-3rgm — Deserialization of untrusted data in Jackson Databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-jjjh-jjxp-wpff — Uncontrolled Resource Consumption in Jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-m6x4-97wx-4q27 — Unsafe Deserialization in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-mc6h-4qgp-37qh — Deserialization of untrusted data in Jackson Databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-mph4-vhrx-mv67 — Deserialization of Untrusted Data in FasterXML jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-mx7p-6679-8g3q — Polymorphic Typing in FasterXML jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-mx9v-gmh4-mgqw — Deserialization of Untrusted Data in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-p43x-xfjf-5jhr — jackson-databind mishandles the interaction between serialization gadgets and typing

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-q93h-jc49-78gg — jackson-databind mishandles the interaction between serialization gadgets and typing

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-qjw2-hr98-qgfh — Unsafe Deserialization in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-qmqc-x3r4-6v39 — Polymorphic deserialization of malicious object in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-qr7j-h6gg-jmgc — Deserialization of Untrusted Data in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-qxxx-2pp7-5hmx — jackson-databind is vulnerable to a deserialization flaw

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-r3gr-cxrf-hg25 — Serialization gadgets exploit in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-r695-7vr9-jgc2 — Unsafe Deserialization in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-rf6r-2c4q-2vwg — jackson-databind mishandles the interaction between serialization gadgets and typing

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-rfx6-vp9g-rh7v — jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist bypass

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-rgv9-q543-rqg4 — Uncontrolled Resource Consumption in FasterXML jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-rpr3-cw39-3pxh — jackson-databind vulnerable to unsafe deserialization

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-v3xw-c963-f5hc — jackson-databind mishandles the interaction between serialization gadgets and typing

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-v585-23hc-c647 — Unsafe Deserialization in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-vfqx-33qm-g869 — Unsafe Deserialization in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-w3f4-3q6j-rh82 — Deserialization of Untrusted Data in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-wh8g-3j2c-rqj5 — Serialization gadgets exploit in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): JacksonSDK vulnerability · info

    GHSA-x2w5-5m2g-7h5m — XML External Entity Reference (XXE) in jackson-databind

    component: jackson

  • Historical CVE on SDK (build version not detected): OkioSDK vulnerability · info

    GHSA-w33c-445m-f8w7 — Okio Signed to Unsigned Conversion Error vulnerability

    component: okio

  • Exported Android componentExported component · info

    im.vector.app.features.login.SSORedirectRouterActivity (activity)

  • Exported Android componentExported component · info

    im.vector.app.features.share.IncomingShareActivity (activity)

  • Exported Android componentExported component · info

    im.vector.app.features.link.LinkHandlerActivity (activity)

  • Exported Android componentExported component · info

    org.jitsi.meet.sdk.ConnectionService (service)

  • Exported Android componentExported component · info

    androidx.work.impl.background.systemjob.SystemJobService (service)

  • Exported Android componentExported component · info

    androidx.sharetarget.ChooserTargetServiceCompat (service)

  • Exported Android componentExported component · info

    androidx.work.impl.diagnostics.DiagnosticsReceiver (receiver)

  • Exported Android componentExported component · info

    androidx.profileinstaller.ProfileInstallReceiver (receiver)

  • Exported Android componentExported component · info

    im.vector.app.core.pushers.VectorUnifiedPushMessagingReceiver (receiver)

  • 1 tracking SDKs detectedTracking SDK · info

    Facebook SDK

  • Data Safety form must declare: Personal infoData Safety obligation · info

    Required by 2 bundled SDK(s): facebook-sdk, sentry. Customer's Play Console Data Safety form must declare this category.

    component: personal_info

  • Data Safety form must declare: App activityData Safety obligation · info

    Required by 1 bundled SDK(s): facebook-sdk. Customer's Play Console Data Safety form must declare this category.

    component: app_activity

  • Data Safety form must declare: App info and performanceData Safety obligation · info

    Required by 1 bundled SDK(s): sentry. Customer's Play Console Data Safety form must declare this category.

    component: app_info_and_performance

  • Data Safety form must declare: Device or other IDsData Safety obligation · info

    Required by 2 bundled SDK(s): facebook-sdk, sentry. Customer's Play Console Data Safety form must declare this category.

    component: device_or_other_ids

Want PR-level context for this app?

Connect the GitHub repo for this app to upgrade to L3. You'll get per-PR Check Runs, source-aware risk factors, and root-cause attribution against this exact bundle.

Compare tiers