Platform Packages Apps Settings vulnerabilities
138 known vulnerabilities affecting platform/packages_apps_settings.
Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN138
Vulnerabilities
Page 2 of 7
CVE-2025-26430P3UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-012025-05-01
CVE-2025-26430 CVE-2025-26430: In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code
In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22428P3UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2025-22428 CVE-2025-22428: In hasInteractAcrossUsersFullPermission of AppInfoBase
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the primary user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43088P3UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 12:0, < 12:2024-11-01+3 more2024-11-01
CVE-2024-43088 CVE-2024-43088: In multiple functions in AppInfoBase
In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due to a missing permission check. This could lead to local escalation of privilege across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20904P3UNKNOWN≥ 12L:0, < 12L:2023-01-01≥ 13:0, < 13:2023-01-012023-01-01
CVE-2023-20904 CVE-2023-20904: In getTrampolineIntent of SettingsActivity
In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31332P3UNKNOWN≥ 14-next:0, < 14-next:2024-07-01≥ 13:0, < 13:2024-07-01+1 more2024-07-01
CVE-2024-31332 CVE-2024-31332: In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check
In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40117P3UNKNOWN≥ 11:0, < 11:2023-10-01≥ 12:0, < 12:2023-10-01+2 more2023-10-01
CVE-2023-40117 CVE-2023-40117: In resetSettingsLocked of SettingsProvider
In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-23704P3UNKNOWN≥ 14-next:0, < 14-next:2024-04-01≥ 13:0, < 13:2024-04-01+1 more2024-04-01
CVE-2024-23704 CVE-2024-23704: In onCreate of WifiDialogActivity
In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40125P3UNKNOWN≥ 14-next:0, < 14-next:2023-10-01≥ 11:0, < 11:2023-10-01+3 more2023-10-01
CVE-2023-40125 CVE-2023-40125: In onCreate of ApnEditor
In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40650P3UNKNOWN≥ 15-next:0, < 15-next:2024-09-01≥ 12:0, < 12:2024-09-01+3 more2024-09-01
CVE-2024-40650 CVE-2024-40650: In wifi_item_edit_content of styles
In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40657P3UNKNOWN≥ 15-next:0, < 15-next:2024-09-01≥ 12:0, < 12:2024-09-01+3 more2024-09-01
CVE-2024-40657 CVE-2024-40657: In addPreferencesForType of AccountTypePreferenceLoader
In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22418P3UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 13:0, < 13:2025-04-01+1 more2025-04-01
CVE-2025-22418 CVE-2025-22418: In multiple locations, there is a possible confused deputy due to Intent Redirect
In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49742P3UNKNOWN≥ 15-next:0, < 15-next:2025-01-01≥ 12:0, < 12:2025-01-01+4 more2025-01-01
CVE-2024-49742 CVE-2024-49742: In onCreate of NotificationAccessConfirmationActivity
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-20955P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 11:0, < 11:2023-03-01+3 more2023-03-01
CVE-2023-20955 CVE-2023-20955: In onPrepareOptionsMenu of AppInfoDashboardFragment
In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and uninstall applications for all users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20360P3UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20360 CVE-2022-20360: In setChecked of SecureNfcPreferenceController
In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21086P3UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 11:0, < 11:2023-04-01+3 more2023-04-01
CVE-2023-21086 CVE-2023-21086: In isToggleable of SecureNfcEnabler
In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20113P3UNKNOWN≥ 12:0, < 12:2022-05-01≥ 12L:0, < 12L:2022-05-012022-05-01
CVE-2022-20113 CVE-2022-20113: In mPreference of DefaultUsbConfigurationPreferenceController
In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20503P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20503 CVE-2022-20503: In onCreate of WifiDppConfiguratorActivity
In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-42544P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-42544 CVE-2022-42544: In getView of AddAppNetworksFragment
In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network add requests due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20508P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20508 CVE-2022-20508: In onAttach of ConfigureWifiSettings
In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21124P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21124 CVE-2023-21124: In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization
In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv