Platform Packages Apps Settings vulnerabilities
138 known vulnerabilities affecting platform/packages_apps_settings.
Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN138
Vulnerabilities
Page 5 of 7
CVE-2021-39707P3UNKNOWN≥ 10:0, < 10:2022-03-01≥ 11:0, < 11:2022-03-01+2 more2022-03-01
CVE-2021-39707 CVE-2021-39707: In onReceive of AppRestrictionsFragment
In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0505P3UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0505 CVE-2021-0505: In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check
In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40654P3UNKNOWN≥ 15-next:0, < 15-next:2024-09-01≥ 12:0, < 12:2024-09-01+3 more2024-09-01
CVE-2024-40654 CVE-2024-40654: In multiple locations, there is a possible permission bypass due to a confused deputy
In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0600P3UNKNOWN≥ 8.1:0, < 8.1:2021-07-01≥ 9:0, < 9:2021-07-01+2 more2021-07-01
CVE-2021-0600 CVE-2021-0600: In onCreate of DeviceAdminAdd
In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39702P3UNKNOWN≥ 12:0, < 12:2022-03-01≥ 12L:0, < 12L:2022-03-012022-03-01
CVE-2021-39702 CVE-2021-39702: In onCreate of RequestManageCredentials
In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates without user approval due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0586P3UNKNOWN≥ 8.1:0, < 8.1:2021-07-01≥ 9:0, < 9:2021-07-01+2 more2021-07-01
CVE-2021-0586 CVE-2021-0586: In onCreate of DevicePickerFragment
In onCreate of DevicePickerFragment.java, there is a possible way to trick the user to select an unwanted bluetooth device due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0593P3UNKNOWN≥ 8.1:0, < 8.1:2021-08-01≥ 9:0, < 9:2021-08-01+2 more2021-08-01
CVE-2021-0593 CVE-2021-0593: In sendDevicePickedIntent of DevicePickerFragment
In sendDevicePickedIntent of DevicePickerFragment.java, there is a possible way to invoke a privileged broadcast receiver due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0333P3UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0333 CVE-2021-0333: In onCreate of BluetoothPermissionActivity
In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permissions dialog when a Bluetooth device is connecting. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20137P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 12:0, < 12:2022-06-01+1 more2022-06-01
CVE-2022-20137 CVE-2022-20137: In onCreateContextMenu of NetworkProviderSettings
In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-20976P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20976 CVE-2023-20976: In getConfirmationMessage of DefaultAutofillPicker
In getConfirmationMessage of DefaultAutofillPicker.java, there is a possible way to mislead the user to select default autofill application due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39669P3UNKNOWN≥ 11:0, < 11:2022-02-01≥ 12:0, < 12:2022-02-012022-02-01
CVE-2021-39669 CVE-2021-39669: In onCreate of InstallCaCertificateWarning
In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circumstances due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0591P3UNKNOWN≥ 8.1:0, < 8.1:2021-08-01≥ 9:0, < 9:2021-08-01+2 more2021-08-01
CVE-2021-0591 CVE-2021-0591: In sendReplyIntentToReceiver of BluetoothPermissionActivity
In sendReplyIntentToReceiver of BluetoothPermissionActivity.java, there is a possible way to invoke privileged broadcast receivers due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0506P3UNKNOWN≥ 8.1:0, < 8.1:2021-06-01≥ 9:0, < 9:2021-06-01+2 more2021-06-01
CVE-2021-0506 CVE-2021-0506: In ActivityPicker
In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0331P3UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0331 CVE-2021-0331: In onCreate of NotificationAccessConfirmationActivity
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0553P3UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0553 CVE-2021-0553: In onBindViewHolder of AppSwitchPreference
In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0769P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0769 CVE-2021-0769: In onCreate of AllowBindAppWidgetActivity
In onCreate of AllowBindAppWidgetActivity.java, there is a possible bypass of user interaction requirements due to unclear UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-1019P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1019 CVE-2021-1019: In snoozeNotification of NotificationListenerService
In snoozeNotification of NotificationListenerService.java, there is a possible permission confusion due to a misleading user consent dialog. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0434P4UNKNOWN≥ 9:0, < 9:2021-11-01≥ 10:0, < 10:2021-11-01+1 more2021-11-01
CVE-2021-0434 CVE-2021-0434: In onReceive of BluetoothPermissionRequest
In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0523P4UNKNOWN≥ 10:0, < 10:2021-06-01≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0523 CVE-2021-0523: In onCreate of WifiScanModeActivity
In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0238P4UNKNOWN≥ 8.0:0, < 8.0:2020-08-01≥ 8.1:0, < 8.1:2020-08-01+2 more2020-08-01
CVE-2020-0238 CVE-2020-0238: In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race condition
In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race condition. This could lead to local escalation of privilege and launching privileged activities with no additional execution privileges needed. User interaction is not needed for exploitation.
osv