Google Android vulnerabilities
9,646 known vulnerabilities affecting google/android.
Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2
Vulnerabilities
Page 154 of 483
CVE-2022-33233HIGHCVSS 7.82023-02-01
CVE-2022-33233 [HIGH] CVE-2022-33233: Closed-source component
Android Security Bulletin 2023-02-01
CVE: CVE-2022-33233
Severity: HIGH
Component: Closed-source component
References: A-240972514
*
android
CVE-2023-20921HIGHCVSS 7.3v10.0v11.0+4 more2023-01-26
CVE-2023-20921 [HIGH] CWE-670 CVE-2023-20921: In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically gra
In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically grant accessibility services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Andr
nvdandroid
CVE-2022-20492HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2022-20492 [HIGH] CWE-770 CVE-2022-20492: In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions setti
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Andro
nvdandroid
CVE-2023-20919HIGHCVSS 7.8v13.0vAndroid-132023-01-26
CVE-2023-20919 [HIGH] CWE-693 CVE-2023-20919: In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation du
In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-252663068
nvdandroid
CVE-2022-20490HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2022-20490 [HIGH] CWE-770 CVE-2022-20490: In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions s
In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L A
nvdandroid
CVE-2023-20912HIGHCVSS 7.8v13.0vAndroid-132023-01-26
CVE-2023-20912 [HIGH] CWE-862 CVE-2023-20912: In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging
In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-2463019
nvdandroid
CVE-2023-20904HIGHCVSS 7.8v12.1v13.0+1 more2023-01-26
CVE-2023-20904 [HIGH] CVE-2023-20904: In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity du
In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-246300272
nvdandroid
CVE-2023-20916HIGHCVSS 7.8v12.0v12.1+1 more2023-01-26
CVE-2023-20916 [HIGH] CWE-862 CVE-2023-20916: In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the re
In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVer
nvdandroid
CVE-2022-20493HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2022-20493 [HIGH] CWE-1284 CVE-2022-20493: In Condition of Condition.java, there is a possible way to grant notification access due to improper
In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID:
nvdandroid
CVE-2022-20489HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2022-20489 [HIGH] CWE-770 CVE-2022-20489: In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions setti
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Andro
nvdandroid
CVE-2022-20461HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2022-20461 [HIGH] CWE-843 CVE-2022-20461: In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of
In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege of BLE with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-
nvdandroid
CVE-2023-20913HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2023-20913 [HIGH] CWE-1021 CVE-2023-20913: In onCreate of PhoneAccountSettingsActivity.java and related files, there is a possible way to misle
In onCreate of PhoneAccountSettingsActivity.java and related files, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Androi
nvdandroid
CVE-2023-20915HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2023-20915 [HIGH] CWE-670 CVE-2023-20915: In addOrReplacePhoneAccount of PhoneAccountRegistrar.java, there is a possible way to enable a phone
In addOrReplacePhoneAccount of PhoneAccountRegistrar.java, there is a possible way to enable a phone account without user interaction due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 And
nvdandroid
CVE-2023-20920HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2023-20920 [HIGH] CWE-416 CVE-2023-20920: In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This
In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-204584366
nvdandroid
CVE-2023-20905HIGHCVSS 7.8v10.0vAndroid-102023-01-26
CVE-2023-20905 [HIGH] CWE-787 CVE-2023-20905: In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a miss
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-241387741
nvdandroid
CVE-2022-20456HIGHCVSS 7.8v10.0v11.0+4 more2023-01-26
CVE-2022-20456 [HIGH] CWE-770 CVE-2022-20456: In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions set
In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L And
nvdandroid
CVE-2023-20922MEDIUMCVSS 5.5v11.0v12.0+3 more2023-01-26
CVE-2023-20922 [MEDIUM] CWE-400 CVE-2023-20922: In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaus
In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-237291548
nvdandroid
CVE-2023-20908MEDIUMCVSS 5.5v10.0v11.0+4 more2023-01-26
CVE-2023-20908 [MEDIUM] CWE-400 CVE-2023-20908: In several functions of SettingsState.java, there is a possible system crash loop due to resource ex
In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-2394158
nvd
CVE-2022-20215MEDIUMCVSS 5.5v10.0v11.0+2 more2023-01-26
CVE-2022-20215 [MEDIUM] CWE-1021 CVE-2022-20215: In onCreate of MasterClearConfirmFragment.java, there is a possible factory reset due to a tapjackin
In onCreate of MasterClearConfirmFragment.java, there is a possible factory reset due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-183794206
nvd
CVE-2022-20213MEDIUMCVSS 5.5v10.0v11.0+2 more2023-01-26
CVE-2022-20213 [MEDIUM] CWE-1021 CVE-2022-20213: In ApplicationsDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/o
In ApplicationsDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-183410508
nvd