cbcvebase.

Platform Packages Apps Settings vulnerabilities

138 known vulnerabilities affecting platform/packages_apps_settings.

Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN138

Vulnerabilities

Page 7 of 7
CVE-2022-20112P4UNKNOWN≥ 10:0, < 10:2022-05-01≥ 11:0, < 11:2022-05-01+2 more2022-05-01
CVE-2022-20112 CVE-2022-20112: In getAvailabilityStatus of PrivateDnsPreferenceController In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20962P4UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-20962 CVE-2023-20962: In getSliceEndItem of MediaVolumePreferenceController In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20425P4UNKNOWN≥ 10:0, < 10:2022-10-01≥ 11:0, < 11:2022-10-012022-10-01
CVE-2022-20425 CVE-2022-20425: In addAutomaticZenRule of ZenModeHelper In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20544P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20544 CVE-2022-20544: In onOptionsItemSelected of ManageApplications In onOptionsItemSelected of ManageApplications.java, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1023P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1023 CVE-2021-1023: In onCreate of RequestIgnoreBatteryOptimizations In onCreate of RequestIgnoreBatteryOptimizations.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-26421P4UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-01+2 more2025-05-01
CVE-2025-26421 CVE-2025-26421: In multiple locations, there is a possible lock screen bypass due to a logic error in the code In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20556P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20556 CVE-2022-20556: In launchConfigNewNetworkFragment of NetworkProviderSettings In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a new WiFi network due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20519P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20519 CVE-2022-20519: In onCreate of AddAppNetworksActivity In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20537P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20537 CVE-2022-20537: In createDialog of WifiScanModeActivity In createDialog of WifiScanModeActivity.java, there is a possible way for a Guest user to enable location-sensitive settings due to a missing permission check. This could lead to local escalation of privilege from the Guest user with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20533P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20533 CVE-2022-20533: In getSlice of WifiSlice In getSlice of WifiSlice.java, there is a possible way to connect a new WiFi network from the guest mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0992P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0992 CVE-2021-0992: In onCreate of PaymentDefaultDialog In onCreate of PaymentDefaultDialog.java, there is a possible way to change a default payment app without user consent due to tapjack overlay. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0459P4UNKNOWN≥ 8.0:0, < 8.0:2020-12-01≥ 8.1:0, < 8.1:2020-12-01+2 more2020-12-01
CVE-2020-0459 CVE-2020-0459: In sendConfiguredNetworkChangedBroadcast of WifiConfigManager In sendConfiguredNetworkChangedBroadcast of WifiConfigManager.java, there is a possible leak of sensitive WiFi configuration data due to a missing permission check. This could lead to local information disclosure of WiFi network names with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20529P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20529 CVE-2022-20529: In multiple locations of WifiDialogActivity In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege in wifi settings with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0983P4UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2021-0983 CVE-2021-0983: In createAdminSupportIntent of DevicePolicyManagerService In createAdminSupportIntent of DevicePolicyManagerService.java, there is a possible disclosure of information about installed device/profile owner package name due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0991P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0991 CVE-2021-0991: In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0095UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 15:0, < 15:2025-02-01+1 more2025-02-01
CVE-2025-0095 CVE-2025-0095: In AppTimeSpentPresenter of AppTimeSpentPreference In AppTimeSpentPresenter of AppTimeSpentPreference.kt, there is a possible way to hijack implicit intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-0094UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 12:0, < 12:2025-02-01+4 more2025-02-01
CVE-2025-0094 CVE-2025-0094: In onCreateOptionsMenu of UserSettings In onCreateOptionsMenu of UserSettings.java, there is a possible way to remove the work profile by opening a hidden activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0091UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 12:0, < 12:2025-02-01+4 more2025-02-01
CVE-2025-0091 CVE-2025-0091: In isSafeIntent of AccountManagerService In isSafeIntent of AccountManagerService.java, there is a possible way to bypass an intent type check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Packages Apps Settings vulnerabilities | cvebase