Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 134 of 339
CVE-2021-0537P3HIGHCVSS 7.3v11.0vAndroid-112021-06-22
CVE-2021-0537 [HIGH] CWE-1021 CVE-2021-0537: In onCreate of WiFiInstaller.java, there is a possible way to install a malicious Hotspot 2.0 config
In onCreate of WiFiInstaller.java, there is a possible way to install a malicious Hotspot 2.0 configuration due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-176756141
nvd
CVE-2021-0538P3HIGHCVSS 7.3v11.0vAndroid-112021-06-22
CVE-2021-0538 [HIGH] CWE-1021 CVE-2021-0538: In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-178821491
nvd
CVE-2021-39691P3HIGHCVSS 7.3v10.0v11.0+2 more2022-06-15
CVE-2021-39691 [HIGH] CWE-1021 CVE-2021-39691: In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when process
In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-157929241
nvd
CVE-2021-1016P3HIGHCVSS 7.3v12.0vAndroid-122021-12-15
CVE-2021-1016 [HIGH] CWE-1021 CVE-2021-1016: In onCreate of UsbPermissionActivity.java, there is a possible way to grant an app access to USB wit
In onCreate of UsbPermissionActivity.java, there is a possible way to grant an app access to USB without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-183610267
nvd
CVE-2021-0583P3HIGHCVSS 7.3v9.0v10.0+1 more2021-10-11
CVE-2021-0583 [HIGH] CWE-1021 CVE-2021-0583: In onCreate of BluetoothPairingDialog, there is a possible way to enable Bluetooth without user cons
In onCreate of BluetoothPairingDialog, there is a possible way to enable Bluetooth without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-182282956
nvd
CVE-2026-0149P3UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0149 CVE-2026-0149: In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This
In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48545P3HIGHCVSS 7.1v13.0v14.0+6 more2025-09-04
CVE-2025-48545 [HIGH] CWE-441 CVE-2025-48545: In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privilege
In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a confused deputy. This could lead to local privilege escalation with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-22009P3HIGHCVSS 7.1v13.0v132024-03-11
CVE-2024-22009 [HIGH] CWE-787 CVE-2024-22009: In init_data of , there is a possible out of bounds write due to a missing bounds check. This could
In init_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32917P3HIGHCVSS 7.1vAndroid kernel2024-06-13
CVE-2024-32917 [HIGH] CWE-787 CVE-2024-32917: In pl330_dma_from_peri_start() of fp_spi_dma.c, there is a possible out of bounds write due to a mis
In pl330_dma_from_peri_start() of fp_spi_dma.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34724P3HIGHCVSS 7.0vAndroid SoC2024-07-09
CVE-2024-34724 [HIGH] CWE-362 CVE-2024-34724: In _UnrefAndMaybeDestroy of pmr.c, there is a possible arbitrary code execution due to a race condit
In _UnrefAndMaybeDestroy of pmr.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48564P3HIGHCVSS 7.0v13.0v14.0+6 more2025-12-08
CVE-2025-48564 [HIGH] CWE-362 CVE-2025-48564: In multiple locations, there is a possible intent filter bypass due to a race condition. This could
In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36916P3HIGHCVSS 7.0vAndroid kernel2025-12-11
CVE-2025-36916 [HIGH] CWE-362 CVE-2025-36916: In PrepareWorkloadBuffers of gxp_main_actor.cc, there is a possible double fetch due to a race condi
In PrepareWorkloadBuffers of gxp_main_actor.cc, there is a possible double fetch due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23709P3MEDIUMCVSS 6.5v12.0v12.1+6 more2024-05-07
CVE-2024-23709 [MEDIUM] CWE-787 CVE-2024-23709: In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This c
In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2024-20044P3MEDIUMCVSS 6.6v12.0v13.0+1 more2024-04-01
CVE-2024-20044 [MEDIUM] CWE-787 CVE-2024-20044: In da, there is a possible out of bounds write due to a missing bounds check. This could lead to loc
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541784; Issue ID: ALPS08541784.
nvd
CVE-2024-20042P3MEDIUMCVSS 6.6v12.0v13.0+1 more2024-04-01
CVE-2024-20042 [MEDIUM] CWE-787 CVE-2024-20042: In da, there is a possible out of bounds write due to a missing bounds check. This could lead to loc
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541780; Issue ID: ALPS08541780.
nvd
CVE-2024-20028P3MEDIUMCVSS 6.6v12.0v13.0+1 more2024-03-04
CVE-2024-20028 [MEDIUM] CWE-787 CVE-2024-20028: In da, there is a possible out of bounds write due to lack of valudation. This could lead to local e
In da, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541687.
nvd
CVE-2024-20054P3MEDIUMCVSS 6.6v13.0v14.02024-04-01
CVE-2024-20054 [MEDIUM] CWE-787 CVE-2024-20054: In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead
In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.
nvd
CVE-2024-20043P3MEDIUMCVSS 6.6v12.0v13.0+1 more2024-04-01
CVE-2024-20043 [MEDIUM] CWE-787 CVE-2024-20043: In da, there is a possible out of bounds write due to a missing bounds check. This could lead to loc
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541781; Issue ID: ALPS08541781.
nvd
CVE-2024-20074P3MEDIUMCVSS 6.6v13.0v14.02024-06-03
CVE-2024-20074 [MEDIUM] CWE-787 CVE-2024-20074: In dmc, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In dmc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08668110; Issue ID: MSV-1333.
nvd
CVE-2025-36912P3MEDIUMCVSS 6.5vAndroid kernel2025-12-11
CVE-2025-36912 [MEDIUM] CVE-2025-36912: In cellular modem, there is a possible denial of service due to a logic error in the code. This coul
In cellular modem, there is a possible denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd