Platform Packages Apps Settings vulnerabilities
138 known vulnerabilities affecting platform/packages_apps_settings.
Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN138
Vulnerabilities
Page 4 of 7
CVE-2023-21024P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21024 CVE-2023-21024: In maybeFinish of FallbackHome
In maybeFinish of FallbackHome.java, there is a possible delay of lockdown screen due to logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21172P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21172 CVE-2023-21172: In multiple functions of WifiCallingSettings
In multiple functions of WifiCallingSettings.java, there is a possible way to change calling preferences for the admin user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-23707P3UNKNOWN≥ 14-next:0, < 14-next:2024-05-01≥ 14:0, < 14:2024-05-012024-05-01
CVE-2024-23707 CVE-2024-23707: In multiple locations, there is a possible permissions bypass due to improper input validation
In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-21135P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21135 CVE-2023-21135: In onCreate of NotificationAccessSettings
In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20349P3UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20349 CVE-2022-20349: In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permissio
In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21005P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21005 CVE-2023-21005: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21015P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21015 CVE-2023-21015: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21003P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21003 CVE-2023-21003: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21004P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21004 CVE-2023-21004: In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check
In getAvailabilityStatus of several Transcode Permission Controllers, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21175P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21175 CVE-2023-21175: In onCreate of DataUsageSummary
In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disable mobile data due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20957P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 11:0, < 11:2023-03-01+2 more2023-03-01
CVE-2023-20957 CVE-2023-20957: In onAttach of SettingsPreferenceFragment
In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20959P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-20959 CVE-2023-20959: In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks
In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22427P3UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2025-22427 CVE-2025-22427: In onCreate of NotificationAccessConfirmationActivity
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above the lock screen due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-21001P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21001 CVE-2023-21001: In onContextItemSelected of NetworkProviderSettings
In onContextItemSelected of NetworkProviderSettings.java, there is a possible way for users to change the Wi-Fi settings of other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21121P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+1 more2023-06-01
CVE-2023-21121 CVE-2023-21121: In onResume of AppManagementFragment
In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40652P3UNKNOWN≥ 15-next:0, < 15-next:2024-09-01≥ 12:0, < 12:2024-09-01+3 more2024-09-01
CVE-2024-40652 CVE-2024-40652: In onCreate of SettingsHomepageActivity
In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0481P3UNKNOWN≥ 8.1:0, < 8.1:2021-05-01≥ 9:0, < 9:2021-05-01+2 more2021-05-01
CVE-2021-0481 CVE-2021-0481: In onActivityResult of EditUserPhotoController
In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39706P3UNKNOWN≥ 10:0, < 10:2022-03-01≥ 11:0, < 11:2022-03-01+2 more2022-03-01
CVE-2021-39706 CVE-2021-39706: In onResume of CredentialStorage
In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0305P3UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0305 CVE-2021-0305: In PackageInstaller, there is a possible tapjacking attack due to an insecure default value
In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-0021P3UNKNOWN≥ 14-next:0, < 14-next:2024-01-01≥ 13:0, < 13:2024-01-01+1 more2024-01-01
CVE-2024-0021 CVE-2024-0021: In onCreate of NotificationAccessConfirmationActivity
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification listener services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv