Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 133 of 339
CVE-2019-20605P3CRITICALCVSS 9.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20605 [CRITICAL] CWE-787 CVE-2019-20605: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets)
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. A heap overflow occurs for baseband in the Shannon modem. The Samsung ID is SVE-2019-14071 (May 2019).
nvd
CVE-2017-18654P3HIGHCVSS 7.5v6.0v7.0+1 more2020-04-07
CVE-2017-18654 [HIGH] CWE-287 CVE-2017-18654: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0, 7.1) software. An unauthent
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0, 7.1) software. An unauthenticated attacker can register a new security certificate. The Samsung ID is SVE-2017-9659 (September 2017).
nvd
CVE-2020-10831P3HIGHCVSS 7.5v8.0v8.1+2 more2020-03-24
CVE-2020-10831 [HIGH] CWE-345 CVE-2020-10831: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attacke
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can trigger an update to arbitrary touch-screen firmware. The Samsung ID is SVE-2019-16013 (March 2020).
nvd
CVE-2018-21065P4CRITICALCVSS 9.8v6.0v7.0+5 more2020-04-08
CVE-2018-21065 [CRITICAL] CWE-191 CVE-2018-21065: An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is an integer underflow in eCryptFS because of a missing size check. The Samsung ID is SVE-2017-11855 (August 2018).
nvd
CVE-2018-21064P4CRITICALCVSS 9.8v7.0v7.1.0+4 more2020-04-08
CVE-2018-21064 [CRITICAL] CWE-120 CVE-2018-21064: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is an array
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is an array overflow in a driver's input booster. The Samsung ID is SVE-2017-11816 (August 2018).
nvd
CVE-2021-0591P3HIGHCVSS 7.3v8.1v9.0+3 more2021-08-17
CVE-2021-0591 [HIGH] CWE-610 CVE-2021-0591: In sendReplyIntentToReceiver of BluetoothPermissionActivity.java, there is a possible way to invoke
In sendReplyIntentToReceiver of BluetoothPermissionActivity.java, there is a possible way to invoke privileged broadcast receivers due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8
nvd
CVE-2022-39908P3HIGHCVSS 7.4v10.0v11.0+2 more2022-12-08
CVE-2022-39908 [HIGH] CWE-367 CVE-2022-39908: TOCTOU vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release
TOCTOU vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.
nvd
CVE-2021-0315P3HIGHCVSS 7.3v8.0v8.1+8 more2021-01-11
CVE-2021-0315 [HIGH] CWE-1021 CVE-2021-0315: In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user
In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Androi
nvd
CVE-2021-0331P3HIGHCVSS 7.3v8.1v9.0+3 more2021-02-10
CVE-2021-0331 [HIGH] CWE-1021 CVE-2021-0331: In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due t
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1
nvd
CVE-2021-0314P3HIGHCVSS 7.3v8.1v9.0+2 more2021-02-10
CVE-2021-0314 [HIGH] CWE-1021 CVE-2021-0314: In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed use
In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android
nvd
CVE-2021-0506P3HIGHCVSS 7.3v8.1v9.0+3 more2021-06-21
CVE-2021-0506 [HIGH] CWE-1021 CVE-2021-0506: In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a
In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-181962311
nvd
CVE-2021-0319P3HIGHCVSS 7.3v8.0v8.1+8 more2021-01-11
CVE-2021-0319 [HIGH] CWE-863 CVE-2021-0319: In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nea
In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass. This could lead to local escalation of privilege that grants access to nearby MAC addresses, with User execution privileges needed. User interaction is needed
nvd
CVE-2022-20126P3HIGHCVSS 7.3v10.0v11.0+3 more2022-06-15
CVE-2022-20126 [HIGH] CWE-862 CVE-2022-20126: In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode wi
In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Andr
nvd
CVE-2021-0553P3HIGHCVSS 7.3v11.0vAndroid-112021-06-22
CVE-2021-0553 [HIGH] CWE-74 CVE-2021-0553: In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin settting
In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169936038
nvd
CVE-2021-39625P3HIGHCVSS 7.3v9.0v10.0+3 more2022-01-14
CVE-2021-39625 [HIGH] CVE-2021-39625: In showCarrierAppInstallationNotification of EuiccNotificationManager.java, there is a possible way
In showCarrierAppInstallationNotification of EuiccNotificationManager.java, there is a possible way to gain an access to MediaProvider content due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android
nvd
CVE-2022-20193P3HIGHCVSS 7.3v12.1vAndroid-12L2022-06-15
CVE-2022-20193 [HIGH] CVE-2022-20193: In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission
In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission attribution due to a logic error in the code. This could lead to local escalation of privilege by conflating apps with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-212434116
nvd
CVE-2021-0769P3HIGHCVSS 7.3v12.0vAndroid-122021-12-15
CVE-2021-0769 [HIGH] CVE-2021-0769: In onCreate of AllowBindAppWidgetActivity.java, there is a possible bypass of user interaction requi
In onCreate of AllowBindAppWidgetActivity.java, there is a possible bypass of user interaction requirements due to unclear UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-184676316
nvd
CVE-2021-1019P3HIGHCVSS 7.3v12.0vAndroid-122021-12-15
CVE-2021-1019 [HIGH] CVE-2021-1019: In snoozeNotification of NotificationListenerService.java, there is a possible permission confusion
In snoozeNotification of NotificationListenerService.java, there is a possible permission confusion due to a misleading user consent dialog. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-195031401
nvd
CVE-2021-0446P3HIGHCVSS 7.3v11.0vAndroid-112021-04-13
CVE-2021-0446 [HIGH] CWE-1021 CVE-2021-0446: In ImportVCardActivity, there is a possible way to bypass user consent due to a tapjacking/overlay a
In ImportVCardActivity, there is a possible way to bypass user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-172252122
nvd
CVE-2021-0441P3HIGHCVSS 7.3v11.0vAndroid-112021-07-14
CVE-2021-0441 [HIGH] CWE-276 CVE-2021-0441: In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI. T
In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174495520
nvd