Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 106 of 339
CVE-2022-20116P3HIGHCVSS 7.8v12.0v12.1+1 more2022-05-10
CVE-2022-20116 [HIGH] CVE-2022-20116: In onEntryUpdated of OngoingCallController.kt, it is possible to launch non-exported activities due
In onEntryUpdated of OngoingCallController.kt, it is possible to launch non-exported activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-212467440
nvd
CVE-2021-0692P3HIGHCVSS 7.8v9.0v10.0+2 more2021-10-06
CVE-2021-0692 [HIGH] CWE-732 CVE-2021-0692: In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to
In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-179289753
nvd
CVE-2021-25510P3HIGHCVSS 7.8v9.0v10.0+1 more2021-12-08
CVE-2021-25510 [HIGH] CWE-20 CVE-2021-25510: An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.
nvd
CVE-2021-39781P3HIGHCVSS 7.8v12.0vAndroid-12L2022-03-30
CVE-2021-39781 [HIGH] CVE-2021-39781: In SmsController, there is a possible information disclosure due to a permissions bypass. This could
In SmsController, there is a possible information disclosure due to a permissions bypass. This could lead to local escalation of privilege and sending sms with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-195311502
nvd
CVE-2021-0953P3HIGHCVSS 7.8v9.0v10.0+3 more2021-12-15
CVE-2021-0953 [HIGH] CWE-281 CVE-2021-0953: In setOnClickActivityIntent of SearchWidgetProvider.java, there is a possible way to access contacts
In setOnClickActivityIntent of SearchWidgetProvider.java, there is a possible way to access contacts and history bookmarks without permission due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-
nvd
CVE-2021-39746P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39746 [HIGH] CVE-2021-39746: In PermissionController, there is a possible way to delete some local files due to an unsafe Pending
In PermissionController, there is a possible way to delete some local files due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-194696395
nvd
CVE-2021-0570P3HIGHCVSS 7.8v11.0vAndroid-112021-06-22
CVE-2021-0570 [HIGH] CWE-732 CVE-2021-0570: In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass
In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-178803845
nvd
CVE-2023-21035P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21035 [HIGH] CWE-863 CVE-2023-21035: In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions pr
In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions previously granted to another app with the same package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers
nvd
CVE-2022-20088P3HIGHCVSS 7.8v11.0v12.02022-05-03
CVE-2022-20088 [HIGH] CWE-755 CVE-2022-20088: In aee driver, there is a possible reference count mistake due to incorrect error handling. This cou
In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS06209201.
nvd
CVE-2021-0568P3HIGHCVSS 7.8v11.0vAndroid-112021-06-22
CVE-2021-0568 [HIGH] CWE-862 CVE-2021-0568: In onReceive of DevicePolicyManagerService.java, there is a possible enabling of disabled profiles d
In onReceive of DevicePolicyManagerService.java, there is a possible enabling of disabled profiles due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-170121238
nvd
CVE-2022-20354P3HIGHCVSS 7.8v11.0v12.0+2 more2022-08-10
CVE-2022-20354 [HIGH] CVE-2022-20354: In onDefaultNetworkChanged of Vpn.java, there is a possible way to disable VPN due to a logic error
In onDefaultNetworkChanged of Vpn.java, there is a possible way to disable VPN due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-219546241
nvd
CVE-2021-39808P3HIGHCVSS 7.8v10.0v11.0+2 more2022-04-12
CVE-2021-39808 [HIGH] CWE-862 CVE-2021-39808: In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service t
In createNotificationChannelGroup of PreferencesHelper.java, there is a possible way for a service to run in foreground without user notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An
nvd
CVE-2021-0985P3HIGHCVSS 7.8v12.0vAndroid-122021-12-15
CVE-2021-0985 [HIGH] CWE-862 CVE-2021-0985: In onReceive of AlertReceiver.java, there is a possible way to dismiss system dialog due to a missin
In onReceive of AlertReceiver.java, there is a possible way to dismiss system dialog due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-190403923
nvd
CVE-2021-1004P3HIGHCVSS 7.8v12.0vAndroid-122021-12-15
CVE-2021-1004 [HIGH] CWE-862 CVE-2021-1004: In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an ap
In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Androi
nvd
CVE-2021-39750P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39750 [HIGH] CWE-862 CVE-2021-39750: In PackageManager, there is a possible way to change the splash screen theme of other apps due to a
In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-206474016
nvd
CVE-2021-39789P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39789 [HIGH] CWE-863 CVE-2021-39789: In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This coul
In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-203880906
nvd
CVE-2021-39743P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39743 [HIGH] CWE-862 CVE-2021-39743: In PackageManager, there is a possible way to update the last usage time of another package due to a
In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-201534884
nvd
CVE-2021-39783P3HIGHCVSS 7.8v12.0vAndroid-12L2022-03-30
CVE-2021-39783 [HIGH] CWE-269 CVE-2021-39783: In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This co
In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-197960597
nvd
CVE-2021-39782P3HIGHCVSS 7.8v12.0vAndroid-12L2022-03-30
CVE-2021-39782 [HIGH] CWE-269 CVE-2021-39782: In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing pe
In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-202760015
nvd
CVE-2021-39758P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39758 [HIGH] CWE-862 CVE-2021-39758: In WindowManager, there is a possible way to start a foreground activity from the background due to
In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-205130886
nvd