Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 107 of 339
CVE-2022-33695P3HIGHCVSS 7.8v10.0v11.0+1 more2022-07-12
CVE-2022-33695 [HIGH] CWE-732 CVE-2022-33695: Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorize
Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.
nvd
CVE-2023-40111P3HIGHCVSS 7.8v14.0v142024-02-15
CVE-2023-40111 [HIGH] CWE-441 CVE-2023-40111: In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending inte
In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-20329P3HIGHCVSS 7.8v13.0vAndroid-132022-08-12
CVE-2022-20329 [HIGH] CWE-862 CVE-2022-20329: In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission chec
In Wifi, there is a possible way to enable Wifi without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-183410556
nvd
CVE-2023-21298P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21298 [HIGH] CWE-203 CVE-2023-21298: In Slice, there is a possible disclosure of installed applications due to side channel information d
In Slice, there is a possible disclosure of installed applications due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20274P3HIGHCVSS 7.8v13.0vAndroid-132022-08-12
CVE-2022-20274 [HIGH] CWE-862 CVE-2022-20274: In Keyguard, there is a missing permission check. This could lead to local escalation of privilege a
In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of screen timeout with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-206470146
nvd
CVE-2023-30916P3HIGHCVSS 7.8v10.0v11.0+2 more2023-07-12
CVE-2023-30916 [HIGH] CWE-862 CVE-2023-30916: In DMService, there is a possible missing permission check. This could lead to local escalation of p
In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2023-30917P3HIGHCVSS 7.8v10.0v11.0+2 more2023-07-12
CVE-2023-30917 [HIGH] CWE-862 CVE-2023-30917: In DMService, there is a possible missing permission check. This could lead to local escalation of p
In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2018-9469P3HIGHCVSS 7.8v7.1.1v7.1.2+7 more2024-11-20
CVE-2018-9469 [HIGH] CWE-862 CVE-2018-9469: In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut du
In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead to local escalation of privilege in a privileged app with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2024-40654P3HIGHCVSS 7.8v12.0v12.1+6 more2024-09-11
CVE-2024-40654 [HIGH] CWE-276 CVE-2024-40654: In multiple locations, there is a possible permission bypass due to a confused deputy. This could le
In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-38464P3HIGHCVSS 7.8v11.02023-09-04
CVE-2023-38464 [HIGH] CWE-862 CVE-2023-38464: In vowifiservice, there is a possible missing permission check.This could lead to local escalation o
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
nvd
CVE-2023-38451P3HIGHCVSS 7.8v11.02023-09-04
CVE-2023-38451 [HIGH] CWE-862 CVE-2023-38451: In vowifiservice, there is a possible missing permission check.This could lead to local escalation o
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
nvd
CVE-2023-38452P3HIGHCVSS 7.8v11.02023-09-04
CVE-2023-38452 [HIGH] CWE-862 CVE-2023-38452: In vowifiservice, there is a possible missing permission check.This could lead to local escalation o
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
nvd
CVE-2023-38460P3HIGHCVSS 7.8v11.02023-09-04
CVE-2023-38460 [HIGH] CWE-862 CVE-2023-38460: In vowifiservice, there is a possible missing permission check.This could lead to local escalation o
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
nvd
CVE-2023-38456P3HIGHCVSS 7.8v11.02023-09-04
CVE-2023-38456 [HIGH] CWE-862 CVE-2023-38456: In vowifiservice, there is a possible missing permission check.This could lead to local escalation o
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
nvd
CVE-2023-38455P3HIGHCVSS 7.8v11.02023-09-04
CVE-2023-38455 [HIGH] CWE-862 CVE-2023-38455: In vowifiservice, there is a possible missing permission check.This could lead to local escalation o
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
nvd
CVE-2023-38449P3HIGHCVSS 7.8v11.02023-09-04
CVE-2023-38449 [HIGH] CWE-862 CVE-2023-38449: In vowifiservice, there is a possible missing permission check.This could lead to local escalation o
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
nvd
CVE-2023-38444P3HIGHCVSS 7.8v11.02023-09-04
CVE-2023-38444 [HIGH] CWE-862 CVE-2023-38444: In vowifiservice, there is a possible missing permission check.This could lead to local escalation o
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
nvd
CVE-2023-38453P3HIGHCVSS 7.8v11.02023-09-04
CVE-2023-38453 [HIGH] CWE-862 CVE-2023-38453: In vowifiservice, there is a possible missing permission check.This could lead to local escalation o
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
nvd
CVE-2023-38450P3HIGHCVSS 7.8v11.02023-09-04
CVE-2023-38450 [HIGH] CWE-862 CVE-2023-38450: In vowifiservice, there is a possible missing permission check.This could lead to local escalation o
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
nvd
CVE-2023-38459P3HIGHCVSS 7.8v11.02023-09-04
CVE-2023-38459 [HIGH] CWE-862 CVE-2023-38459: In vowifiservice, there is a possible missing permission check.This could lead to local escalation o
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
nvd