Platform Packages Apps Settings vulnerabilities
138 known vulnerabilities affecting platform/packages_apps_settings.
Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN138
Vulnerabilities
Page 1 of 7
CVE-2023-20960P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 12L:0, < 12L:2023-03-01+1 more2023-03-01
CVE-2023-20960 CVE-2023-20960: In launchDeepLinkIntentToRight of SettingsHomepageActivity
In launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20946P3UNKNOWN≥ 11:0, < 11:2023-02-01≥ 12:0, < 12:2023-02-01+2 more2023-02-01
CVE-2023-20946 CVE-2023-20946: In onStart of BluetoothSwitchPreferenceController
In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20347P3UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20347 CVE-2022-20347: In onAttach of ConnectedDeviceDashboardFragment
In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2026-0021P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+3 more2026-03-01
CVE-2026-0021 CVE-2026-0021: In hasInteractAcrossUsersFullPermission of AppInfoBase
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible cross-user permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0965P3UNKNOWN≥ 9:0, < 9:2021-12-01≥ 10:0, < 10:2021-12-01+2 more2021-12-01
CVE-2021-0965 CVE-2021-0965: In AndroidManifest
In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48541P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48541 CVE-2025-48541: In onCreate of FaceSettings
In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0416P3UNKNOWN≥ 8.0:0, < 8.0:2020-10-01≥ 8.1:0, < 8.1:2020-10-01+2 more2020-10-01
CVE-2020-0416 CVE-2020-0416: In multiple settings screens, there are possible tapjacking attacks due to an insecure default value
In multiple settings screens, there are possible tapjacking attacks due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-48535P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48535 CVE-2025-48535: In assertSafeToStartCustomActivity of AppRestrictionsFragment
In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a launch anywhere vulnerability due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2026-0017P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 16:0, < 16:2026-03-01+1 more2026-03-01
CVE-2026-0017 CVE-2026-0017: In onChange of BiometricService
In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48531P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48531 CVE-2025-48531: In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code
In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22422P3UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2025-22422 CVE-2025-22422: In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app when its result will be used in a
In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app when its result will be used in another due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed
osv
CVE-2025-32333P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 14:0, < 14:2025-09-012025-09-01
CVE-2025-32333 CVE-2025-32333: In startSpaActivityForApp of SpaActivity
In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32326P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-32326 CVE-2025-32326: In multiple functions of AppRestrictionsFragment
In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-32321P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-32321 CVE-2025-32321: In isSafeIntent of AccountTypePreferenceLoader
In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32347P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-32347 CVE-2025-32347: In onStart of BiometricEnrollIntroduction
In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-48599P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 13:0, < 13:2025-12-01+1 more2025-12-01
CVE-2025-48599 CVE-2025-48599: In multiple functions of WifiScanModeActivity
In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21248P3UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 12:0, < 12:2023-07-01+2 more2023-07-01
CVE-2023-21248 CVE-2023-21248: In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController
In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32345P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+1 more2025-09-01
CVE-2025-32345 CVE-2025-32345: In updateState of ContentProtectionTogglePreferenceController
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40677P3UNKNOWN≥ 15-next:0, < 15-next:2024-10-01≥ 12:0, < 12:2024-10-01+3 more2024-10-01
CVE-2024-40677 CVE-2024-40677: In shouldSkipForInitialSUW of AdvancedPowerUsageDetail
In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26435P3UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-012025-05-01
CVE-2025-26435 CVE-2025-26435: In updateState of ContentProtectionTogglePreferenceController
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
1 / 7Next →