VYPR

Settings

by Samsung Mobile

CVEs (9)

  • CVE-2026-20979HigFeb 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege.

  • CVE-2019-20620HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. The Settings application allows unauthenticated changes. The Samsung IDs are SVE-2019-13814, SVE-2019-13815 (March 2019).

  • CVE-2023-42530MedNov 7, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper access control vulnerability in SecSettings prior to SMR Nov-2023 Release 1 allows attackers to enable Wi-Fi and Wi-Fi Direct without User Interaction.

  • CVE-2023-30727MedOct 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi and connect arbitrary Wi-Fi without User Interaction.

  • CVE-2026-20988MedMar 16, 2026
    risk 0.33cvss 5.0epss 0.00

    Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability.

  • CVE-2023-30708MedSep 6, 2023
    risk 0.30cvss 4.6epss 0.01

    Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.

  • CVE-2025-20909MedMar 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2022-39904LowDec 8, 2022
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.

  • CVE-2022-30729LowJun 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a malicious QR code scanner.