Platform Packages Modules Connectivity vulnerabilities
5 known vulnerabilities affecting platform/packages_modules_connectivity.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN5
Vulnerabilities
Page 1 of 1
CVE-2025-26445UNKNOWN≥ 16-next:0, < 16-next:2025-06-01≥ 15:0, < 15:2025-06-01+2 more2025-06-01
CVE-2025-26445 CVE-2025-26445: In offerNetwork of ConnectivityService
In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49734UNKNOWN≥ 15-next:0, < 15-next:2025-01-01≥ 15:0, < 15:2025-01-01+1 more2025-01-01
CVE-2024-49734 CVE-2024-49734: In multiple functions of ConnectivityService
In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to through a VPN due to side channel information disclosure. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20929UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-20929 CVE-2023-20929: In sendHalfSheetCancelBroadcast of HalfSheetActivity
In sendHalfSheetCancelBroadcast of HalfSheetActivity.java, there is a possible way to learn nearby BT MAC addresses due to an unrestricted broadcast intent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20145UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-012022-06-01
CVE-2022-20145 CVE-2022-20145: In startLegacyVpnPrivileged of Vpn
In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0994UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0994 CVE-2021-0994: In requestRouteToHostAddress of ConnectivityService
In requestRouteToHostAddress of ConnectivityService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv