Platform Packages Apps Nfc vulnerabilities

14 known vulnerabilities affecting platform/packages_apps_nfc.

Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
UNKNOWN14

Vulnerabilities

Page 1 of 1
CVE-2021-39810UNKNOWN≥ 13:0, < 13:2025-09-012025-09-01
CVE-2021-39810 CVE-2021-39810: In verifyDefaults of CardEmulationManager In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35671UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 11:0, < 11:2023-09-01+3 more2023-09-01
CVE-2023-35671 CVE-2023-35671: In onHostEmulationData of HostEmulationManager In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21183UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21183 CVE-2023-21183: In ForegroundUtils of ForegroundUtils In ForegroundUtils of ForegroundUtils.java, there is a possible way to read NFC tag data while the app is still in the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20945UNKNOWN≥ 10:0, < 10:2023-02-012023-02-01
CVE-2023-20945 CVE-2023-20945: In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20905UNKNOWN≥ 10:0, < 10:2023-01-012023-01-01
CVE-2023-20905 CVE-2023-20905: In Mfc_Transceive of phNxpExtns_MifareStd In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20199UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20199 CVE-2022-20199: In multiple locations of NfcService In multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20123UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 10:0, < 10:2022-06-01+3 more2022-06-01
CVE-2022-20123 CVE-2022-20123: In phNciNfc_RecvMfResp of phNxpExtns_MifareStd In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0996UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0996 CVE-2021-0996: In nfaHciCallback of HciEventManager In nfaHciCallback of HciEventManager.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over NFC with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0956UNKNOWNExploited≥ 11:0, < 11:2021-12-01≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0956 CVE-2021-0956: In NfcTag::discoverTechnologies (activation) of NfcTag In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0598UNKNOWN≥ 8.1:0, < 8.1:2021-09-01≥ 9:0, < 9:2021-09-01+2 more2021-09-01
CVE-2021-0598 CVE-2021-0598: In onCreate of ConfirmConnectActivity In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0594UNKNOWN≥ 8.1:0, < 8.1:2021-07-01≥ 9:0, < 9:2021-07-01+2 more2021-07-01
CVE-2021-0594 CVE-2021-0594: In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validation In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to improper input validation. This could lead to remote (proximal, NFC) escalation of privilege allowing an attacker to deceive a user into allowing a Bluetooth connection with no additional execution privileges needed. User interaction is needed for explo
osv
CVE-2021-0596UNKNOWN≥ 8.1:0, < 8.1:2021-07-01≥ 9:0, < 9:2021-07-01+2 more2021-07-01
CVE-2021-0596 CVE-2021-0596: In phNciNfc_RecvMfResp of phNxpExtns_MifareStd In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0542UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0542 CVE-2021-0542: In updateNotification of BeamTransferManager In updateNotification of BeamTransferManager.java, there is a missing permission check. This could lead to local information disclosure of paired Bluetooth addresses with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0453UNKNOWN≥ 8.0:0, < 8.0:2020-11-01≥ 8.1:0, < 8.1:2020-11-01+1 more2020-11-01
CVE-2020-0453 CVE-2020-0453: In updateNotification of BeamTransferManager In updateNotification of BeamTransferManager.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local non-security issue with User execution privileges needed. User interaction is not needed for exploitation.
osv