Google Android vulnerabilities
9,646 known vulnerabilities affecting google/android.
Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2
Vulnerabilities
Page 104 of 483
CVE-2023-24853HIGHCVSS 8.42023-10-01
CVE-2023-24853 [HIGH] CVE-2023-24853: Closed-source component
Android Security Bulletin 2023-10-01
CVE: CVE-2023-24853
Severity: HIGH
Component: Closed-source component
References: A-276751372
*
android
CVE-2023-33027HIGHCVSS 7.52023-10-01
CVE-2023-33027 [HIGH] CVE-2023-33027: Closed-source component
Android Security Bulletin 2023-10-01
CVE: CVE-2023-33027
Severity: HIGH
Component: Closed-source component
References: A-290061249
*
android
CVE-2022-28348HIGHCVSS 9.82023-10-01
CVE-2022-28348 [CRITICAL] CVE-2022-28348: Mali
Android Security Bulletin 2023-10-01
CVE: CVE-2022-28348
Severity: HIGH
Component: Mali
References: A-296463357
*
android
CVE-2023-4211HIGHCVSS 5.5KEV2023-10-01
CVE-2023-4211 [MEDIUM] CVE-2023-4211: Mali
Android Security Bulletin 2023-10-01
CVE: CVE-2023-4211
Severity: HIGH
Component: Mali
References: A-294605494
*
android
CVE-2023-24847HIGHCVSS 7.52023-10-01
CVE-2023-24847 [HIGH] CVE-2023-24847: Closed-source component
Android Security Bulletin 2023-10-01
CVE: CVE-2023-24847
Severity: HIGH
Component: Closed-source component
References: A-276751090
*
android
CVE-2021-44828HIGHCVSS 7.82023-10-01
CVE-2021-44828 [HIGH] CVE-2021-44828: Mali
Android Security Bulletin 2023-10-01
CVE: CVE-2021-44828
Severity: HIGH
Component: Mali
References: A-296461583
*
android
CVE-2023-24850HIGHCVSS 7.82023-10-01
CVE-2023-24850 [HIGH] CVE-2023-24850: Closed-source component
Android Security Bulletin 2023-10-01
CVE: CVE-2023-24850
Severity: HIGH
Component: Closed-source component
References: A-276751108
*
android
CVE-2023-33029HIGHCVSS 8.42023-10-01
CVE-2023-33029 [HIGH] CVE-2023-33029: Kernel
Android Security Bulletin 2023-10-01
CVE: CVE-2023-33029
Severity: HIGH
Component: Kernel
References: A-290061916
QC-CR#3446314
android
CVE-2023-44123HIGHCVSS 7.8v12.0v13.02023-09-27
CVE-2023-44123 [HIGH] CWE-285 CVE-2023-44123: The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that
The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Bluetooth ("com.lge.bluetoothsetting") app. The attacker's app, if it had access to app notifications, could intercept them and redirect them to its activity, before mak
nvd
CVE-2023-44122HIGHCVSS 7.8v12.0v13.02023-09-27
CVE-2023-44122 [HIGH] CWE-927 CVE-2023-44122: The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("c
The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is that the app launches implicit intents that can be intercepted by third-party apps installed on the same device.
nvd
CVE-2023-44125HIGHCVSS 7.8v12.0v13.02023-09-27
CVE-2023-44125 [HIGH] CWE-285 CVE-2023-44125: The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set
The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app. The attacker's app, if it had access to app notifications, could intercept them and redirect them to its activity, before
nvd
CVE-2023-44126MEDIUMCVSS 5.5≥ 8.0, ≤ 13.02023-09-27
CVE-2023-44126 [MEDIUM] CWE-925 CVE-2023-44126: The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends
The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned implicit broadcasts that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as call states, durations, called numbers, contacts info, etc.
nvd
CVE-2023-44127MEDIUMCVSS 5.5≥ 8.0, ≤ 13.02023-09-27
CVE-2023-44127 [MEDIUM] CWE-927 CVE-2023-44127: he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launch
he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents that disclose sensitive data to all third-party apps installed on the same device. Those intents include data such as contact details and phone numbers.
nvd
CVE-2023-44216MEDIUMCVSS 5.3v13.02023-09-27
CVE-2023-44216 [MEDIUM] CWE-203 CVE-2023-44216: PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transpar
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one ori
nvd
CVE-2023-44121MEDIUMCVSS 6.3≥ 9.0, ≤ 13.02023-09-27
CVE-2023-44121 [MEDIUM] CWE-926 CVE-2023-44121: The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/
The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a third-party app installed on an LG device by sending a broadcast with the action "com.lge.lms.things.notification.ACTION". Additionally, this vulnerabili
nvd
CVE-2023-44128LOWCVSS 3.6≥ 4.0, ≤ 13.02023-09-27
CVE-2023-44128 [LOW] CWE-367 CVE-2023-44128: he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app.
he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the exported "com.lge.lginstallservies.InstallService" service that exposes an AIDL interface. All its "installPackage*" methods are finally calling the "installPackageVerify()" method that performs signature validation after the delete f
nvd
CVE-2023-44129LOWCVSS 3.3≥ 12.0, ≤ 13.02023-09-27
CVE-2023-44129 [LOW] CWE-926 CVE-2023-44129: The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-cont
The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity. The attacker can abuse this functionality by launching this activity and then sending a broadcast with the "com.lge.message.action.QCLIP" actio
nvd
CVE-2023-44124LOWCVSS 3.3v12.0v13.02023-09-27
CVE-2023-44124 [LOW] CWE-927 CVE-2023-44124: The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com
The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settings/ProfilePreferenceFragment.java" file. The main problem is that the app launches implicit intents that can be intercepted by third-party apps installed on the same device. T
nvd
CVE-2023-35681CRITICALCVSS 9.8v13.0v132023-09-11
CVE-2023-35681 [CRITICAL] CWE-190 CVE-2023-35681: In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an i
In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2023-35682HIGHCVSS 7.8v11.0v12.0+6 more2023-09-11
CVE-2023-35682 [HIGH] CVE-2023-35682: In hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary
In hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary components due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvdandroid