VYPR

Settings

by Google

CVEs (13)

  • CVE-2025-48535HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a launch anywhere vulnerability due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution…

  • CVE-2025-26430HigSep 4, 2025
    risk 0.51cvss 7.8epss 0.00

    In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-22418HigSep 2, 2025
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-43087HigNov 13, 2024
    risk 0.51cvss 7.8epss 0.00

    In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error in the code. This could lead to local escalation of privilege with no additional…

  • CVE-2024-40650HigSep 11, 2024
    risk 0.51cvss 7.8epss 0.00

    In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21389HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21388HigOct 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21256HigJul 13, 2023
    risk 0.51cvss 7.8epss 0.00

    In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-0020MedFeb 16, 2024
    risk 0.36cvss 5.5epss 0.00

    In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional execution privileges needed.…

  • CVE-2023-21325MedOct 30, 2023
    risk 0.36cvss 5.5epss 0.00

    In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed…

  • CVE-2023-21311MedOct 30, 2023
    risk 0.36cvss 5.5epss 0.00

    In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35677MedSep 11, 2023
    risk 0.36cvss 5.5epss 0.00

    In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not…

  • CVE-2014-8609Dec 15, 2014
    risk 0.00cvss epss 0.01

    The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not properly create a PendingIntent, which allows attackers to use the SYSTEM uid for broadcasting an intent with arbitrary component,…