cbcvebase.

Platform Packages Apps Settings vulnerabilities

138 known vulnerabilities affecting platform/packages_apps_settings.

Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN138

Vulnerabilities

Page 6 of 7
CVE-2025-48598P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 16:0, < 16:2025-12-012025-12-01
CVE-2025-48598 CVE-2025-48598: In multiple locations, there is a possible way to alter the primary user's face unlock settings due to a confused deputy In multiple locations, there is a possible way to alter the primary user's face unlock settings due to a confused deputy. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48527P4UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48527 CVE-2025-48527: In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the code In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0020P4UNKNOWN≥ 14-next:0, < 14-next:2024-01-01≥ 11:0, < 11:2024-01-01+4 more2024-01-01
CVE-2024-0020 CVE-2024-0020: In onActivityResult of NotificationSoundPreference In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26442P4UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-01+2 more2025-05-01
CVE-2025-26442 CVE-2025-26442: In onCreate of NotificationAccessConfirmationActivity In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20396P4UNKNOWN≥ 13-next:0, < 13-next:2022-09-01≥ 12L:0, < 12L:2022-09-01+1 more2022-09-01
CVE-2022-20396 CVE-2022-20396: In SettingsActivity In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21173P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21173 CVE-2023-21173: In multiple methods of DataUsageList In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0386P4UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0386 CVE-2020-0386: In onCreate of RequestPermissionActivity In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0396P4UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0396 CVE-2020-0396: In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20515P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20515 CVE-2022-20515: In onPreferenceClick of AccountTypePreferenceLoader In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20350P4UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20350 CVE-2022-20350: In onCreate of NotificationAccessConfirmationActivity In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20353P4UNKNOWN≥ 10:0, < 10:2022-08-01≥ 11:0, < 11:2022-08-01+2 more2022-08-01
CVE-2022-20353 CVE-2022-20353: In onSaveRingtone of DefaultRingtonePreference In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49736P4UNKNOWN≥ 12:0, < 12:2025-01-01≥ 12L:0, < 12L:2025-01-01+2 more2025-01-01
CVE-2024-49736 CVE-2024-49736: In onClick of MainClear In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39631P4UNKNOWN≥ 10:0, < 10:2022-02-05≥ 11:0, < 11:2022-02-05+1 more2022-02-01
CVE-2021-39631 CVE-2021-39631: In clear_data_dlg_text of strings In clear_data_dlg_text of strings.xml, there is a possible situation when "Clear storage" functionality sets up the wrong security/privacy expectations due to a misleading message. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0552P4UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0552 CVE-2021-0552: In getEndItemSliceAction of MediaOutputSlice In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20466P4UNKNOWN≥ 12:0, < 12:2022-12-01≥ 12L:0, < 12L:2022-12-01+1 more2022-12-01
CVE-2022-20466 CVE-2022-20466: In applyKeyguardFlags of NotificationShadeWindowControllerImpl In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the user's password on a secondary display due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-35677P4UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 11:0, < 11:2023-09-01+3 more2023-09-01
CVE-2023-35677 CVE-2023-35677: In onCreate of DeviceAdminAdd In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21016P4UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21016 CVE-2023-21016: In AccountTypePreference of AccountTypePreference In AccountTypePreference of AccountTypePreference.java, there is a possible way to mislead the user about accounts installed on the device due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21091P4UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 13:0, < 13:2023-04-012023-04-01
CVE-2023-21091 CVE-2023-21091: In canDisplayLocalUi of AppLocalePickerActivity In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26432P4UNKNOWN≥ 16-next:0, < 16-next:2025-06-012025-06-01
CVE-2025-26432 CVE-2025-26432: In multiple locations, there is a possible way to persistently DoS the device due to a missing length check In multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1012P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1012 CVE-2021-1012: In onResume of NotificationAccessDetails In onResume of NotificationAccessDetails.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Packages Apps Settings vulnerabilities | cvebase