cbcvebase.

Platform Packages Apps Settings vulnerabilities

138 known vulnerabilities affecting platform/packages_apps_settings.

Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN138

Vulnerabilities

Page 2 of 7
CVE-2025-26430P3UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-012025-05-01
CVE-2025-26430 CVE-2025-26430: In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22428P3UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2025-22428 CVE-2025-22428: In hasInteractAcrossUsersFullPermission of AppInfoBase In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the primary user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43088P3UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 12:0, < 12:2024-11-01+3 more2024-11-01
CVE-2024-43088 CVE-2024-43088: In multiple functions in AppInfoBase In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due to a missing permission check. This could lead to local escalation of privilege across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20904P3UNKNOWN≥ 12L:0, < 12L:2023-01-01≥ 13:0, < 13:2023-01-012023-01-01
CVE-2023-20904 CVE-2023-20904: In getTrampolineIntent of SettingsActivity In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31332P3UNKNOWN≥ 14-next:0, < 14-next:2024-07-01≥ 13:0, < 13:2024-07-01+1 more2024-07-01
CVE-2024-31332 CVE-2024-31332: In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40117P3UNKNOWN≥ 11:0, < 11:2023-10-01≥ 12:0, < 12:2023-10-01+2 more2023-10-01
CVE-2023-40117 CVE-2023-40117: In resetSettingsLocked of SettingsProvider In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-23704P3UNKNOWN≥ 14-next:0, < 14-next:2024-04-01≥ 13:0, < 13:2024-04-01+1 more2024-04-01
CVE-2024-23704 CVE-2024-23704: In onCreate of WifiDialogActivity In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40125P3UNKNOWN≥ 14-next:0, < 14-next:2023-10-01≥ 11:0, < 11:2023-10-01+3 more2023-10-01
CVE-2023-40125 CVE-2023-40125: In onCreate of ApnEditor In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40650P3UNKNOWN≥ 15-next:0, < 15-next:2024-09-01≥ 12:0, < 12:2024-09-01+3 more2024-09-01
CVE-2024-40650 CVE-2024-40650: In wifi_item_edit_content of styles In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40657P3UNKNOWN≥ 15-next:0, < 15-next:2024-09-01≥ 12:0, < 12:2024-09-01+3 more2024-09-01
CVE-2024-40657 CVE-2024-40657: In addPreferencesForType of AccountTypePreferenceLoader In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22418P3UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 13:0, < 13:2025-04-01+1 more2025-04-01
CVE-2025-22418 CVE-2025-22418: In multiple locations, there is a possible confused deputy due to Intent Redirect In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49742P3UNKNOWN≥ 15-next:0, < 15-next:2025-01-01≥ 12:0, < 12:2025-01-01+4 more2025-01-01
CVE-2024-49742 CVE-2024-49742: In onCreate of NotificationAccessConfirmationActivity In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-20955P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 11:0, < 11:2023-03-01+3 more2023-03-01
CVE-2023-20955 CVE-2023-20955: In onPrepareOptionsMenu of AppInfoDashboardFragment In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and uninstall applications for all users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20360P3UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20360 CVE-2022-20360: In setChecked of SecureNfcPreferenceController In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21086P3UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 11:0, < 11:2023-04-01+3 more2023-04-01
CVE-2023-21086 CVE-2023-21086: In isToggleable of SecureNfcEnabler In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20113P3UNKNOWN≥ 12:0, < 12:2022-05-01≥ 12L:0, < 12L:2022-05-012022-05-01
CVE-2022-20113 CVE-2022-20113: In mPreference of DefaultUsbConfigurationPreferenceController In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20503P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20503 CVE-2022-20503: In onCreate of WifiDppConfiguratorActivity In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-42544P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-42544 CVE-2022-42544: In getView of AddAppNetworksFragment In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network add requests due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20508P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20508 CVE-2022-20508: In onAttach of ConfigureWifiSettings In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21124P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21124 CVE-2023-21124: In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Packages Apps Settings vulnerabilities | cvebase