VYPR

platform/frameworks/base

by Google

CVEs (49)

  • CVE-2021-0517HigJun 21, 2021
    risk 0.49cvss 7.5epss 0.01

    In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determination due to a logic error in the code. This could lead to biasing of networking tasks to occur on non-VPN networks, which could lead to remote information disclosure, with no…

  • CVE-2025-48594HigDec 8, 2025
    risk 0.47cvss 7.3epss 0.00

    In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2025-32319MedDec 8, 2025
    risk 0.44cvss 6.7epss 0.00

    In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions due to a permissions bypass. This could lead to local escalation of privilege with user execution privileges needed. User interaction is not needed for…

  • CVE-2025-48550MedSep 4, 2025
    risk 0.36cvss 5.5epss 0.00

    In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path traversal error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-26463MedSep 4, 2025
    risk 0.36cvss 5.5epss 0.00

    In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This could lead to a local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-22430MedSep 2, 2025
    risk 0.36cvss 5.5epss 0.00

    In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-43084MedNov 13, 2024
    risk 0.36cvss 5.5epss 0.00

    In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-31312MedJul 9, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposing played media with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-0026MedMay 7, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-0022MedMay 7, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges…

  • CVE-2024-0047MedMar 11, 2024
    risk 0.36cvss 5.5epss 0.00

    In writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This could lead to local denial of service when policies are deserialized on reboot with no additional execution privileges needed. User interaction…

  • CVE-2023-40124MedFeb 15, 2024
    risk 0.36cvss 5.5epss 0.00

    In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40092MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40081MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-40076MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.02

    In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-40075MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In forceReplaceShortcutInner of ShortcutPackage.java, there is a possible way to register unlimited packages due to a missing bounds check. This could lead to local denial of service which results in a boot loop with no additional execution privileges needed. User interaction is…

  • CVE-2023-40073MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35668MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40133MedOct 27, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40123MedOct 27, 2023
    risk 0.36cvss 5.5epss 0.00

    In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.