Google Android vulnerabilities
9,646 known vulnerabilities affecting google/android.
Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2
Vulnerabilities
Page 136 of 483
CVE-2023-21098HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21098 [HIGH] CWE-288 CVE-2023-21098: In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code i
In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Androi
nvdandroid
CVE-2023-21086HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21086 [HIGH] CVE-2023-21086: In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible
In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers
nvdandroid
CVE-2023-21081HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21081 [HIGH] CVE-2023-21081: In multiple functions of PackageInstallerService.java and related files, there is a possible way to
In multiple functions of PackageInstallerService.java and related files, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11
nvdandroid
CVE-2023-20967HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-20967 [HIGH] CWE-787 CVE-2023-20967: In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an in
In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-22
nvdandroid
CVE-2023-21089HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21089 [HIGH] CVE-2023-21089: In startInstrumentation of ActivityManagerService.java, there is a possible way to keep the foregrou
In startInstrumentation of ActivityManagerService.java, there is a possible way to keep the foreground service alive while the app is in the background. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L And
nvdandroid
CVE-2023-21100HIGHCVSS 7.8v12.0v12.1+2 more2023-04-19
CVE-2023-21100 [HIGH] CWE-787 CVE-2023-21100: In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This
In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-242544249
nvdandroid
CVE-2023-21092HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21092 [HIGH] CWE-20 CVE-2023-21092: In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a B
In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver using permissions of System App due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:
nvdandroid
CVE-2023-20950HIGHCVSS 7.8v11.0v12.0+2 more2023-04-19
CVE-2023-20950 [HIGH] CWE-863 CVE-2023-20950: In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background a
In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restrictions via a pendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L
nvdandroid
CVE-2023-21093HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21093 [HIGH] CWE-22 CVE-2023-21093: In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory bel
In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 A
nvdandroid
CVE-2023-20935MEDIUMCVSS 5.5v11.0v12.0+3 more2023-04-19
CVE-2023-20935 [MEDIUM] CWE-125 CVE-2023-20935: In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds che
In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-256589724
nvdandroid
CVE-2023-21080MEDIUMCVSS 5.5v11.0v12.0+3 more2023-04-19
CVE-2023-21080 [MEDIUM] CWE-125 CVE-2023-21080: In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing
In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-245916076
nvdandroid
CVE-2023-20909MEDIUMCVSS 5.5v11.0v12.0+3 more2023-04-19
CVE-2023-20909 [MEDIUM] CWE-862 CVE-2023-20909: In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missin
In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-2431
nvdandroid
CVE-2023-21082MEDIUMCVSS 5.5v11.0v12.0+3 more2023-04-19
CVE-2023-21082 [MEDIUM] CWE-441 CVE-2023-21082: In getNumberFromCallIntent of NewOutgoingCallIntentBroadcaster.java, there is a possible way to enum
In getNumberFromCallIntent of NewOutgoingCallIntentBroadcaster.java, there is a possible way to enumerate other user's contact phone number due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 An
nvdandroid
CVE-2023-21087MEDIUMCVSS 5.5v11.0v12.0+3 more2023-04-19
CVE-2023-21087 [MEDIUM] CWE-248 CVE-2023-21087: In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. T
In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. This could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-261723753
nvdandroid
CVE-2023-21091MEDIUMCVSS 5.5v13.0vAndroid-132023-04-19
CVE-2023-21091 [MEDIUM] CWE-862 CVE-2023-21091: In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app l
In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:
nvdandroid
CVE-2023-21084MEDIUMCVSS 6.7v13.0vAndroid-132023-04-19
CVE-2023-21084 [MEDIUM] CVE-2023-21084: In buildPropFile of filesystem.go, there is a possible insecure hash due to an improperly used crypt
In buildPropFile of filesystem.go, there is a possible insecure hash due to an improperly used crypto. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262892300
nvdandroid
CVE-2023-21090MEDIUMCVSS 5.0v13.0vAndroid-132023-04-19
CVE-2023-21090 [MEDIUM] CWE-400 CVE-2023-21090: In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource ex
In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-259942609
nvdandroid
CVE-2022-47338HIGHCVSS 7.1v10.0v11.02023-04-11
CVE-2022-47338 [HIGH] CWE-668 CVE-2022-47338: In telecom service, there is a missing permission check. This could lead to local denial of service
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
nvdandroid
CVE-2022-47468MEDIUMCVSS 5.5v10.0v11.02023-04-11
CVE-2022-47468 [MEDIUM] CWE-476 CVE-2022-47468: In telecom service, there is a missing permission check. This could lead to local denial of service
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
nvd
CVE-2022-47335MEDIUMCVSS 5.5v10.0v11.0+2 more2023-04-11
CVE-2022-47335 [MEDIUM] CWE-120 CVE-2022-47335: In telecom service, there is a missing permission check. This could lead to local denial of service
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
nvdandroid