Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16246 | A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. |
Wed, 07 Oct 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 07 Oct 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. | A vulnerability was identified in PhonePe App 25.03.21.0 on Android. This affects an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. The attack needs to be performed locally. The exploit is publicly available and might be used. The actual existence of this vulnerability is currently in question. The root-requirement of the attack is reflected by the CVSS vector attribute PR:H. The vendor explains: "[A]s per the PoC this vulnerability needs a rooted device to exploit. PhonePe does not consider vulnerabilities found in rooted device as valid because there is not real-world exploit scenario." |
| Title | PhonePe App SQLite Database databases cleartext storage in a file or on disk | PhonePe App SQLite Database databases cleartext storage in file |
| First Time appeared |
Phonepe App
Phonepe App phonepe App |
|
| CPEs | cpe:2.3:a:phonepe_app:phonepe_app:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Phonepe App
Phonepe App phonepe App |
|
| References |
| |
| Metrics |
cvssV2_0
|
cvssV2_0
|
Tue, 03 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phonepe
Phonepe phonepe |
|
| CPEs | cpe:2.3:a:phonepe:phonepe:25.03.21.0:*:*:*:*:android:*:* | |
| Vendors & Products |
Phonepe
Phonepe phonepe |
Wed, 28 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 25 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. | |
| Title | PhonePe App SQLite Database databases cleartext storage in a file or on disk | |
| Weaknesses | CWE-312 CWE-313 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-07T06:34:14.634Z
Reserved: 2025-05-24T22:19:52.467Z
Link: CVE-2025-5154
Updated: 2025-05-27T14:21:06.543Z
Status : Modified
Published: 2025-05-25T19:15:19.740
Modified: 2026-10-07T07:16:56.067
Link: CVE-2025-5154
No data.
OpenCVE Enrichment
No data.
EUVD