cbcvebase.

Google Android vulnerabilities

9,713 known vulnerabilities affecting google/android.

Total CVEs
9,713
CISA KEV
49
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5220MEDIUM3343LOW265UNKNOWN2

Vulnerabilities

Page 12 of 486
CVE-2025-36912MEDIUMCVSS 6.5vAndroid kernel2025-12-11
CVE-2025-36912 [MEDIUM] CVE-2025-36912: In cellular modem, there is a possible denial of service due to a logic error in the code. This coul In cellular modem, there is a possible denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36922MEDIUMCVSS 6.7vAndroid kernel2025-12-11
CVE-2025-36922 [MEDIUM] CWE-416 CVE-2025-36922: In bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. Th In bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. This could lead to local escalation of privilege in the OS Kernel level with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36938MEDIUMCVSS 6.8vAndroid kernel2025-12-11
CVE-2025-36938 [MEDIUM] CWE-693 CVE-2025-36938: In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the cod In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36917MEDIUMCVSS 6.5vAndroid kernel2025-12-11
CVE-2025-36917 [MEDIUM] CWE-120 CVE-2025-36917: In SwDcpItg of up_L2commonPdcpSecurity.cpp, there is a possible denial of service due to an incorrec In SwDcpItg of up_L2commonPdcpSecurity.cpp, there is a possible denial of service due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36929MEDIUMCVSS 5.5vAndroid kernel2025-12-11
CVE-2025-36929 [MEDIUM] CWE-20 CVE-2025-36929: In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48626CRITICALCVSS 9.8v13.0v14.0+6 more2025-12-08
CVE-2025-48626 [CRITICAL] CWE-693 CVE-2025-48626: In multiple locations, there is a possible way to launch an application from the background due to a In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-48573HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48573 [HIGH] CWE-250 CVE-2025-48573: In sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service In sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service while the app is in the background due to FGS while-in-use abuse. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-32328HIGHCVSS 7.8v13.0v14.0+4 more2025-12-08
CVE-2025-32328 [HIGH] CVE-2025-32328: In multiple functions of Session.java, there is a possible way to view images belonging to a differe In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-48621HIGHCVSS 7.3v13.0v14.0+6 more2025-12-08
CVE-2025-48621 [HIGH] CWE-1188 CVE-2025-48621: In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a ins In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvdandroid
CVE-2025-48572HIGHCVSS 7.8KEVv13.0v14.0+6 more2025-12-08
CVE-2025-48572 [HIGH] CWE-306 CVE-2025-48572: In multiple locations, there is a possible way to launch activities from the background due to a per In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-22420HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-22420 [HIGH] CWE-441 CVE-2025-22420: In multiple locations, there is a possible way to leak audio files across user profiles due to a con In multiple locations, there is a possible way to leak audio files across user profiles due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-48555HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48555 [HIGH] CWE-441 CVE-2025-48555: In multiple functions of NotificationStation.java, there is a possible cross-profile information dis In multiple functions of NotificationStation.java, there is a possible cross-profile information disclosure due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-48594HIGHCVSS 7.3v14.0v15.0+4 more2025-12-08
CVE-2025-48594 [HIGH] CWE-20 CVE-2025-48594: In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion appl In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvdandroid
CVE-2025-48639HIGHCVSS 7.3v13.0v14.0+6 more2025-12-08
CVE-2025-48639 [HIGH] CWE-1021 CVE-2025-48639: In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvdandroid
CVE-2025-48629HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48629 [HIGH] CWE-1188 CVE-2025-48629: In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech recognizer app due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-48628HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48628 [HIGH] CWE-441 CVE-2025-48628: In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak d In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-48637HIGHCVSS 7.8vAndroid kernel2025-12-08
CVE-2025-48637 [HIGH] CWE-190 CVE-2025-48637: In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer ov In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-48632HIGHCVSS 7.8v14.0v15.0+4 more2025-12-08
CVE-2025-48632 [HIGH] CWE-20 CVE-2025-48632: In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to p In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated them due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-32329HIGHCVSS 7.8v13.0v14.0+4 more2025-12-08
CVE-2025-32329 [HIGH] CVE-2025-32329: In multiple functions of Session.java, there is a possible way to view images belonging to a differe In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-48624HIGHCVSS 7.8vAndroid kernel2025-12-08
CVE-2025-48624 [HIGH] CWE-787 CVE-2025-48624: In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper inpu In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid