Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 120 of 339
CVE-2023-40090P3MEDIUMCVSS 6.5v11.0v12.0+8 more2023-12-04
CVE-2023-40090 [MEDIUM] CWE-203 CVE-2023-40090: In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due
In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26441P3MEDIUMCVSS 6.5v13.0v14.0+4 more2025-09-04
CVE-2025-26441 [MEDIUM] CWE-125 CVE-2025-26441: In add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds chec
In add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0041P3MEDIUMCVSS 6.5v14.0v15.0+8 more2026-06-01
CVE-2026-0041 [MEDIUM] CWE-190 CVE-2026-0041: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an int
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2017-18665P3HIGHCVSS 8.8v6.02020-04-07
CVE-2017-18665 [HIGH] CWE-476 CVE-2017-18665: An issue was discovered on Samsung mobile devices with M(6.0) software. There is a NULL pointer exce
An issue was discovered on Samsung mobile devices with M(6.0) software. There is a NULL pointer exception in WifiService via adb-cmd, causing memory corruption. The Samsung ID is SVE-2017-8287 (June 2017).
nvd
CVE-2016-3749P3HIGHCVSS 8.4v6.0v6.0.12016-07-11
CVE-2016-3749 [HIGH] CWE-255 CVE-2016-3749: server/LockSettingsService.java in LockSettingsService in Android 6.x before 2016-07-01 allows attac
server/LockSettingsService.java in LockSettingsService in Android 6.x before 2016-07-01 allows attackers to modify the screen-lock password or pattern via a crafted application, aka internal bug 28163930.
nvd
CVE-2016-0844P3HIGHCVSS 8.4v6.0v6.0.12016-04-18
CVE-2016-0844 [HIGH] CWE-264 CVE-2016-0844: The Qualcomm RF driver in Android 6.x before 2016-04-01 does not properly restrict access to socket
The Qualcomm RF driver in Android 6.x before 2016-04-01 does not properly restrict access to socket ioctl calls, which allows attackers to gain privileges via a crafted application, aka internal bug 26324307.
nvd
CVE-2016-0807P3HIGHCVSS 8.4v6.0v6.0.12016-02-07
CVE-2016-0807 [HIGH] CWE-264 CVE-2016-0807: The get_build_id function in elf_utils.cpp in Debuggerd in Android 6.x before 2016-02-01 allows atta
The get_build_id function in elf_utils.cpp in Debuggerd in Android 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application that mishandles a Desc Size element in an ELF Note, aka internal bug 25187394.
nvd
CVE-2016-0843P3HIGHCVSS 8.4v4.0v4.0.1+20 more2016-04-18
CVE-2016-0843 [HIGH] CWE-264 CVE-2016-0843: The Qualcomm ARM processor performance-event manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2
The Qualcomm ARM processor performance-event manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application, aka internal bug 25801197.
nvd
CVE-2016-0848P3HIGHCVSS 8.4v4.0v4.0.1+20 more2016-04-18
CVE-2016-0848 [HIGH] CWE-362 CVE-2016-0848: Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1
Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-access restrictions via a crafted application that changes a symlink target, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26211054.
nvd
CVE-2013-6272P3HIGHCVSS 7.8≥ 4.1.1, ≤ 4.4.22018-05-02
CVE-2013-6272 [HIGH] CWE-284 CVE-2013-6272: The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 thr
The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application.
nvd
CVE-2017-0386P3HIGHCVSS 7.8v5.0v5.0.1+8 more2017-01-12
CVE-2017-0386 [HIGH] CVE-2017-0386: An elevation of privilege vulnerability in the libnl library could enable a local malicious applicat
An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Version
nvd
CVE-2017-18647P3HIGHCVSS 8.1v6.0v6.0.1+1 more2020-04-07
CVE-2017-18647 [HIGH] CWE-362 CVE-2017-18647: An issue was discovered on Samsung mobile devices with M(6,x) and N(7.0) software. The TA Scrypto v1
An issue was discovered on Samsung mobile devices with M(6,x) and N(7.0) software. The TA Scrypto v1.0 implementation in Secure Driver has a race condition with a resultant buffer overflow. The Samsung IDs are SVE-2017-8973, SVE-2017-8974, and SVE-2017-8975 (November 2017).
nvd
CVE-2016-11030P3HIGHCVSS 8.1v4.4v5.0+2 more2020-04-07
CVE-2016-11030 [HIGH] CWE-362 CVE-2016-11030: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) (with Hrm sen
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) (with Hrm sensor support) software. The sysfs of the MAX86902 sensor driver does not prevent concurrent access, leading to a race condition and resultant heap-based buffer overflow. The Samsung ID is SVE-2016-7341 (December 2016).
nvd
CVE-2017-0417P3HIGHCVSS 7.8v4.0v4.0.1+26 more2017-02-08
CVE-2017-0417 [HIGH] CWE-787 CVE-2017-0417: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versi
nvd
CVE-2017-0415P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-02-08
CVE-2017-0415 [HIGH] CVE-2017-0415: An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to
An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 6.0
nvd
CVE-2017-0419P3HIGHCVSS 7.8v4.0v4.0.1+26 more2017-02-08
CVE-2017-0419 [HIGH] CVE-2017-0419: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4
nvd
CVE-2017-0418P3HIGHCVSS 7.8v4.0v4.0.1+26 more2017-02-08
CVE-2017-0418 [HIGH] CWE-787 CVE-2017-0418: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versi
nvd
CVE-2017-0416P3HIGHCVSS 7.8v4.0v4.0.1+26 more2017-02-08
CVE-2017-0416 [HIGH] CWE-787 CVE-2017-0416: An elevation of privilege vulnerability in Audioserver could enable a local malicious application to
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versi
nvd
CVE-2016-6704P3HIGHCVSS 7.8≥ 4.0, < 4.4.4≥ 5.0, < 5.0.2+3 more2016-11-25
CVE-2016-6704 [HIGH] CWE-264 CVE-2016-6704: An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0
An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local ac
nvd
CVE-2017-0749P3HIGHCVSS 7.8≤ 7.1.22017-08-09
CVE-2017-0749 [HIGH] CVE-2017-0749: A elevation of privilege vulnerability in the Upstream Linux linux kernel. Product: Android. Version
A elevation of privilege vulnerability in the Upstream Linux linux kernel. Product: Android. Versions: Android kernel. Android ID: A-36007735.
nvd