cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 141 of 339
CVE-2021-39796P4HIGHCVSS 7.3v10.0v11.0+3 more2022-04-12
CVE-2021-39796 [HIGH] CWE-1021 CVE-2021-39796: In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick vic In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-1
nvd
CVE-2022-20501P4HIGHCVSS 7.3v10.0v11.0+4 more2022-12-13
CVE-2022-20501 [HIGH] CWE-1021 CVE-2022-20501: In onCreate of EnableAccountPreferenceActivity.java, there is a possible way to mislead the user int In onCreate of EnableAccountPreferenceActivity.java, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11
nvd
CVE-2021-0598P4HIGHCVSS 7.3v8.1v9.0+3 more2021-10-06
CVE-2021-0598 [HIGH] CWE-1021 CVE-2021-0598: In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devic In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-
nvd
CVE-2021-0523P4HIGHCVSS 7.3v10.0v11.0+1 more2021-06-21
CVE-2021-0523 [HIGH] CWE-1021 CVE-2021-0523: In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without u In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-174047492
nvd
CVE-2026-0139P3UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0139 CVE-2026-0139: In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0146P3UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0146 CVE-2026-0146: In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0147P3UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0147 CVE-2026-0147: In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-6606P4CRITICALCVSS 9.3≤ 5.12015-10-06
CVE-2015-6606 [CRITICAL] CWE-264 CVE-2015-6606: The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 22301786.
nvd
CVE-2015-6619P4CRITICALCVSS 9.3≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-6619 [CRITICAL] CWE-264 CVE-2015-6619: The kernel in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privile The kernel in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, aka internal bug 23520714.
nvd
CVE-2015-3865P4CRITICALCVSS 9.3≤ 5.12015-10-06
CVE-2015-3865 [CRITICAL] CWE-264 CVE-2015-3865: The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a craft The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23050463.
nvd
CVE-2015-7717P4CRITICALCVSS 9.3≤ 5.12015-10-06
CVE-2015-7717 [CRITICAL] CVE-2015-7717: mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain pr mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.
nvd
CVE-2015-6623P4CRITICALCVSS 9.3v6.02015-12-08
CVE-2015-6623 [CRITICAL] CWE-264 CVE-2015-6623: Wi-Fi in Android 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application Wi-Fi in Android 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24872703.
nvd
CVE-2025-48533P4HIGHCVSS 7.0v13.0v14.0+6 more2025-09-04
CVE-2025-48533 [HIGH] CWE-362 CVE-2025-48533: In multiple locations, there is a possible way to use apps linked from a context menu of a lockscree In multiple locations, there is a possible way to use apps linked from a context menu of a lockscreen app due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48641P4HIGHCVSS 7.0v14.0v15.0+5 more2026-03-02
CVE-2025-48641 [HIGH] CWE-362 CVE-2025-48641: In multiple functions of Nfc.h, there is a possible use after free due to a race condition. This cou In multiple functions of Nfc.h, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22442P3HIGHCVSS 7.0v13.0v14.0+4 more2025-09-02
CVE-2025-22442 [HIGH] CWE-362 CVE-2025-22442: In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unautho In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications into a newly created work profile due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48625P3HIGHCVSS 7.0v16.0v16-qpr22025-12-08
CVE-2025-48625 [HIGH] CWE-362 CVE-2025-48625: In multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB d In multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB data when the screen is off due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2017-13203P4CRITICALCVSS 9.1v6.0v6.0.1+5 more2018-01-12
CVE-2017-13203 [CRITICAL] CWE-200 CVE-2017-13203: An information disclosure vulnerability in the Android media framework (libavc). Product: Android. V An information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-63122634.
nvd
CVE-2017-13204P4CRITICALCVSS 9.1v6.0v6.0.1+5 more2018-01-12
CVE-2017-13204 [CRITICAL] CWE-200 CVE-2017-13204: An information disclosure vulnerability in the Android media framework (libavc). Product: Android. V An information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64380237.
nvd
CVE-2017-13188P4CRITICALCVSS 9.1v5.1.1v6.0+6 more2018-01-12
CVE-2017-13188 [CRITICAL] CWE-200 CVE-2017-13188: An information disclosure vulnerability in the Android media framework (aac). Product: Android. Vers An information disclosure vulnerability in the Android media framework (aac). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65280786.
nvd
CVE-2017-13205P4CRITICALCVSS 9.1v6.0v6.0.1+5 more2018-01-12
CVE-2017-13205 [CRITICAL] CWE-200 CVE-2017-13205: An information disclosure vulnerability in the Android media framework (libmpeg2). Product: Android. An information disclosure vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64550583.
nvd