Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 1 of 339
CVE-2025-48543P1HIGHCVSS 8.8KEVPoCv13.0v14.0+6 more2025-09-04
CVE-2025-48543 [HIGH] CWE-416 CVE-2025-48543: In multiple locations, there is a possible way to escape chrome sandbox to attack android system_ser
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20963P1HIGHCVSS 7.8KEVPoCv11.0v12.0+3 more2023-03-24
CVE-2023-20963 [HIGH] CWE-295 CVE-2023-20963: In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519
nvd
CVE-2011-1823P1HIGHCVSS 7.8KEV≥ 2.0, < 2.3.4v3.02011-06-09
CVE-2011-1823 [HIGH] CWE-190 CVE-2011-1823: The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received
The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruptio
nvd
CVE-2025-48595P1HIGHCVSS 8.4KEVv14.0v15.0+8 more2026-06-01
CVE-2025-48595 [HIGH] CWE-190 CVE-2025-48595: In multiple locations, there is a possible way to achieve code execution due to an integer overflow.
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48572P1HIGHCVSS 7.8KEVv13.0v14.0+6 more2025-12-08
CVE-2025-48572 [HIGH] CWE-306 CVE-2025-48572: In multiple locations, there is a possible way to launch activities from the background due to a per
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32896P1HIGHCVSS 7.8KEVvAndroid kernel2024-06-13
CVE-2024-32896 [HIGH] CWE-670 CVE-2024-32896: there is a possible way to bypass due to a logic error in the code. This could lead to local escala
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-35674P1HIGHCVSS 7.8KEVv11.0v12.0+6 more2023-09-11
CVE-2023-35674 [HIGH] CWE-269 CVE-2023-35674: In onCreate of WindowState.java, there is a possible way to launch a background activity due to a lo
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29748P1HIGHCVSS 7.8KEVfixed in 2024-04-05vAndroid kernel2024-04-05
CVE-2024-29748 [HIGH] CWE-755 CVE-2024-29748: there is a possible way to bypass due to a logic error in the code. This could lead to local escala
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-22265P1HIGHCVSS 7.8KEVv9.0v10.0+2 more2022-01-10
CVE-2022-22265 [HIGH] CWE-703 CVE-2022-22265: An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
nvd
CVE-2024-43093P1HIGHCVSS 7.3KEVv12.0v12.1+8 more2024-11-13
CVE-2024-43093 [HIGH] CWE-176 CVE-2024-43093: In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path fil
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-48633P1MEDIUMCVSS 5.5KEVv13.0v14.0+6 more2025-12-08
CVE-2025-48633 [MEDIUM] CVE-2025-48633: In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29745P2MEDIUMCVSS 5.5KEVvAndroid kernel2024-04-05
CVE-2024-29745 [MEDIUM] CWE-908 CVE-2024-29745: there is a possible Information Disclosure due to uninitialized data. This could lead to local infor
there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21237P2MEDIUMCVSS 5.5KEVv13.0vAndroid-132023-06-28
CVE-2023-21237 [MEDIUM] CWE-200 CVE-2023-21237: In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground s
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A
nvd
CVE-2010-1807P2CRITICALCVSS 9.3ExploitedPoC≤ 2.1v1.0+4 more2010-09-10
CVE-2010-1807 [CRITICAL] CWE-20 CVE-2010-1807: WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk befo
WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to non-standard NaN representation.
nvd
CVE-2017-13156P1HIGHCVSS 7.8ExploitedPoCv5.1.1v6.0+5 more2017-12-06
CVE-2017-13156 [HIGH] CWE-434 CVE-2017-13156: An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.
nvd
CVE-2016-0728P2HIGHCVSS 7.8ExploitedPoCv4.0v4.0.1+22 more2016-02-08
CVE-2016-0728 [HIGH] CVE-2016-0728: The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 m
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.
nvd
CVE-2018-5383P1MEDIUMCVSS 6.8ExploitedRansomwarev6.0v6.0.1+5 more2018-08-07
CVE-2018-5383 [MEDIUM] CWE-325 CVE-2018-5383: Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra
Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encr
nvd
CVE-2023-40088P2HIGHCVSS 8.8Exploitedv11.0v12.0+8 more2023-12-04
CVE-2023-40088 [HIGH] CWE-416 CVE-2023-40088: In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible
In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2017-13315P1HIGHCVSS 7.8Exploitedv6.0v6.0.1+10 more2024-11-19
CVE-2017-13315 [HIGH] CWE-131 CVE-2017-13315: In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a w
In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. This could lead to an elevation of privileges where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2014-9792P2HIGHCVSS 7.8Exploited≤ 6.0.12016-07-11
CVE-2014-9792 [HIGH] CWE-189 CVE-2014-9792: arch/arm/mach-msm/ipc_router.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 de
arch/arm/mach-msm/ipc_router.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices uses an incorrect integer data type, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769399 and Qualcomm internal bug CR550606.
nvd
1 / 339Next →