VYPR

SettingsProvider

by Google

CVEs (5)

  • CVE-2023-40117HigOct 27, 2023
    risk 0.51cvss 7.8epss 0.00

    In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-48608MedDec 8, 2025
    risk 0.36cvss 5.5epss 0.00

    In isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2021-39747MedMar 30, 2022
    risk 0.36cvss 5.5epss 0.00

    In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20255MedAug 12, 2022
    risk 0.29cvss 4.4epss 0.00

    In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-24925MedFeb 11, 2022
    risk 0.29cvss 4.4epss 0.00

    Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of service attack on a victim's devices.