Platform Packages Apps Documentsui vulnerabilities

4 known vulnerabilities affecting platform/packages_apps_documentsui.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN4

Vulnerabilities

Page 1 of 1
CVE-2026-0013UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+2 more2026-03-01
CVE-2026-0013 CVE-2026-0013: In setupLayout of PickActivity In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32323UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-32323 CVE-2025-32323: In getCallingAppName of Shared In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text in a permission popup due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22439UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2025-22439 CVE-2025-22439: In onLastAccessedStackLoaded of ActionHandler In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-43765UNKNOWN≥ 15-next:0, < 15-next:2025-01-01≥ 12:0, < 12:2025-01-01+4 more2025-01-01
CVE-2024-43765 CVE-2024-43765: In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv