Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 12 of 339
CVE-2018-9413P3HIGHCVSS 8.8v7.0v7.1.1+5 more2024-12-02
CVE-2018-9413 [HIGH] CWE-787 CVE-2018-9413: In handle_notification_response of btif_rc.cc, there is a possible out of bounds write due to a miss
In handle_notification_response of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-48530P3HIGHCVSS 8.1v16.0v162025-09-04
CVE-2025-48530 [HIGH] CWE-125 CVE-2025-48530: In multiple locations, there is a possible condition that results in OOB accesses due to an incorrec
In multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This could lead to remote code execution in combination with other bugs, with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9446P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-11-06
CVE-2018-9446 [CRITICAL] CWE-787 CVE-2018-9446: In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memo
In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Andro
nvd
CVE-2019-2036P3CRITICALCVSS 9.8v8.0v8.1+3 more2019-11-13
CVE-2019-2036 [CRITICAL] CVE-2019-2036: In okToConnect of HidHostService.java, there is a possible permission bypass due to an incorrect sta
In okToConnect of HidHostService.java, there is a possible permission bypass due to an incorrect state check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-79703832
nvd
CVE-2018-9556P3CRITICALCVSS 9.8v9.02018-12-06
CVE-2018-9556 [CRITICAL] CWE-190 CVE-2018-9556: In ParsePayloadHeader of payload_metadata.cc, there is a possible out of bounds write due to an inte
In ParsePayloadHeader of payload_metadata.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113118184.
nvd
CVE-2021-0516P3CRITICALCVSS 9.8v8.1v9.0+3 more2021-06-21
CVE-2021-0516 [CRITICAL] CWE-125 CVE-2021-0516: In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a
In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-1816604
nvd
CVE-2019-2047P3CRITICALCVSS 9.8v7.0v7.1.1+5 more2019-05-08
CVE-2019-2047 [CRITICAL] CWE-787 CVE-2019-2047: In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This c
In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 And
nvd
CVE-2019-2046P3CRITICALCVSS 9.8v7.0v7.1.1+5 more2019-05-08
CVE-2019-2046 [CRITICAL] CWE-190 CVE-2019-2046: In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an
In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 An
nvd
CVE-2021-39708P3CRITICALCVSS 9.8v12.0vAndroid-122022-03-16
CVE-2021-39708 [CRITICAL] CWE-787 CVE-2021-39708: In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorr
In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-206128341
nvd
CVE-2021-25387P3CRITICALCVSS 10.0v8.1v9.0+2 more2021-06-11
CVE-2021-25387 [CRITICAL] CWE-122 CVE-2021-25387: An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior t
An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
nvd
CVE-2019-9365P3CRITICALCVSS 9.8v10.0vAndroid-102019-09-27
CVE-2019-9365 [CRITICAL] CWE-502 CVE-2019-9365: In Bluetooth, there is a possible deserialization error due to missing string validation. This could
In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-109838537
nvd
CVE-2023-20918P3CRITICALCVSS 9.8v11.0v12.0+6 more2023-07-13
CVE-2023-20918 [CRITICAL] CWE-611 CVE-2023-20918: In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege d
In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20083P3CRITICALCVSS 9.8v12.02024-08-14
CVE-2024-20083 [CRITICAL] CWE-787 CVE-2024-20083: In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08810810 / ALPS08805789; Issue ID: MSV-1502.
nvd
CVE-2014-7224P3HIGHCVSS 8.8fixed in 4.42020-02-07
CVE-2014-7224 [HIGH] CWE-20 CVE-2014-7224: A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterfac
A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicious user execute arbitrary code.
nvd
CVE-2026-0106P3CRITICALCVSS 9.3vAndroid kernel2026-02-05
CVE-2026-0106 [CRITICAL] CWE-119 CVE-2026-0106: In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check.
In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49749P3HIGHCVSS 8.8v12.0v12.1+8 more2025-01-21
CVE-2024-49749 [HIGH] CWE-787 CVE-2024-49749: In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This
In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9472P3HIGHCVSS 8.8v7.0v7.1.1+7 more2024-11-20
CVE-2018-9472 [HIGH] CWE-190 CVE-2018-9472: In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflo
In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2018-9365P3HIGHCVSS 8.8v6.0v6.0.1+5 more2024-11-19
CVE-2018-9365 [HIGH] CWE-125 CVE-2018-9365: In smp_data_received of smp_l2c.cc, there is a possible out of bounds read followed by code executio
In smp_data_received of smp_l2c.cc, there is a possible out of bounds read followed by code execution due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2018-9433P3HIGHCVSS 8.8v6.0v6.0.1+7 more2024-11-19
CVE-2018-9433 [HIGH] CWE-116 CVE-2018-9433: In ArrayConcatVisitor of builtins-array.cc, there is a possible type confusion due to improper input
In ArrayConcatVisitor of builtins-array.cc, there is a possible type confusion due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-20960P3HIGHCVSS 8.8v12.1v13.0+1 more2023-03-24
CVE-2023-20960 [HIGH] CWE-20 CVE-2023-20960: In launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch a
In launchDeepLinkIntentToRight of SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-25
nvd