Google Android vulnerabilities
9,713 known vulnerabilities affecting google/android.
Total CVEs
9,713
CISA KEV
49
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5216MEDIUM3347LOW265UNKNOWN2
Vulnerabilities
Page 1 of 486
CVE-2026-0088HIGHCVSS 7.8v16-qpr2v16+2 more2026-06-01
CVE-2026-0088 [HIGH] CWE-451 CVE-2026-0088: In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security di
In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48649HIGHCVSS 7.8v16-qpr2v16+2 more2026-06-01
CVE-2025-48649 [HIGH] CWE-693 CVE-2025-48649: In multiple locations, there is a possible way to reset user-selected permissions selections due to
In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0087HIGHCVSS 7.8v16-qpr2v16+2 more2026-06-01
CVE-2026-0087 [HIGH] CWE-693 CVE-2026-0087: In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hija
In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0097HIGHCVSS 8.0v14.0v15.0+5 more2026-06-01
CVE-2026-0097 [HIGH] CWE-693 CVE-2026-0097: In multiple locations, there is a possible way to bypass user interaction when pairing an LE device
In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-28577HIGHCVSS 7.8v14.0v15.0+5 more2026-06-01
CVE-2026-28577 [HIGH] CWE-1021 CVE-2026-28577: In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/
In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0045HIGHCVSS 7.8v16-qpr2v16+2 more2026-06-01
CVE-2026-0045 [HIGH] CWE-693 CVE-2026-0045: In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connec
In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0076HIGHCVSS 7.8v14.0v15.0+5 more2026-06-01
CVE-2026-0076 [HIGH] CWE-125 CVE-2026-0076: In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bou
In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0059HIGHCVSS 8.0v14.0v15.0+5 more2026-06-01
CVE-2026-0059 [HIGH] CWE-122 CVE-2026-0059: In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to
In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0095HIGHCVSS 8.0v16-qpr2v16+2 more2026-06-01
CVE-2026-0095 [HIGH] CWE-190 CVE-2026-0095: In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption wi
In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0094HIGHCVSS 7.8v16-qpr2v16+2 more2026-06-01
CVE-2026-0094 [HIGH] CWE-451 CVE-2026-0094: In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into appr
In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48595HIGHCVSS 8.4KEVv14.0v15.0+5 more2026-06-01
CVE-2025-48595 [HIGH] CWE-190 CVE-2025-48595: In multiple locations, there is a possible way to achieve code execution due to an integer overflow.
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-28580HIGHCVSS 7.8v16.0v16-qpr2+1 more2026-06-01
CVE-2026-28580 [HIGH] CWE-120 CVE-2026-28580: In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. T
In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0096HIGHCVSS 7.8v16.0v16-qpr2+1 more2026-06-01
CVE-2026-0096 [HIGH] CWE-451 CVE-2026-0096: In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgettin
In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48570HIGHCVSS 7.8v14.0v142026-06-01
CVE-2025-48570 [HIGH] CWE-441 CVE-2025-48570: In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from t
In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22424HIGHCVSS 7.8v14.0v15.0+5 more2026-06-01
CVE-2025-22424 [HIGH] CVE-2025-22424: In multiple locations, there is a possible way to reveal images across users due to improper input v
In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2026-0098HIGHCVSS 7.8v14.0v15.0+5 more2026-06-01
CVE-2026-0098 [HIGH] CWE-441 CVE-2026-0098: In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictio
In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0100HIGHCVSS 7.8v14.0v15.0+5 more2026-06-01
CVE-2026-0100 [HIGH] CWE-122 CVE-2026-0100: In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. Th
In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0093HIGHCVSS 7.8v16-qpr2v16+2 more2026-06-01
CVE-2026-0093 [HIGH] CWE-451 CVE-2026-0093: In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to loca
In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48652HIGHCVSS 7.8v15.0v16.0+3 more2026-06-01
CVE-2025-48652 [HIGH] CWE-693 CVE-2025-48652: In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due
In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0078HIGHCVSS 7.8v16-qpr2v16+2 more2026-06-01
CVE-2026-0078 [HIGH] CWE-20 CVE-2026-0078: In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due
In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
1 / 486Next →