Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 155 of 339
CVE-2016-11026P4HIGHCVSS 7.5v4.4v5.0+2 more2020-04-07
CVE-2016-11026 [HIGH] CWE-755 CVE-2016-11026: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. Boo
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. BootReceiver allows attackers to trigger a system crash because of incorrect exception handling. The Samsung ID is SVE-2016-7118 (December 2016).
nvd
CVE-2017-18663P4HIGHCVSS 7.5v7.0v7.1.0+2 more2020-04-07
CVE-2017-18663 [HIGH] CWE-755 CVE-2017-18663: An issue was discovered on Samsung mobile devices with N(7.x) software. Because of missing Intent ex
An issue was discovered on Samsung mobile devices with N(7.x) software. Because of missing Intent exception handling, system_server can have a NullPointerException with a crash of a system process. The Samsung IDs are SVE-2017-9122, SVE-2017-9123, SVE-2017-9124, and SVE-2017-9126 (July 2017).
nvd
CVE-2017-18678P4HIGHCVSS 7.5v4.4v5.0+6 more2020-04-07
CVE-2017-18678 [HIGH] CWE-755 CVE-2017-18678: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) softw
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. An attacker can crash system processes via a Serializable object because of missing exception handling. The Samsung IDs are SVE-2017-8109, SVE-2017-8110, SVE-2017-8115, SVE-2017-8118, and SVE-2017-8119 (April 2017).
nvd
CVE-2017-18664P4HIGHCVSS 7.5v4.4v5.0+2 more2020-04-07
CVE-2017-18664 [HIGH] CWE-476 CVE-2017-18664: An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. The
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. There is a NULL pointer exception in PersonManager, causing memory corruption. The Samsung ID is SVE-2017-8286 (June 2017).
nvd
CVE-2018-21059P4HIGHCVSS 7.5v7.0v7.1.0+4 more2020-04-08
CVE-2018-21059 [HIGH] CWE-200 CVE-2018-21059: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is Clipboar
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is Clipboard content visibility in the locked state via the emergency contact picker. The Samsung ID is SVE-2018-11806 (September 2018).
nvd
CVE-2020-25056P4HIGHCVSS 7.5v10.02020-08-31
CVE-2020-25056 [HIGH] CWE-754 CVE-2020-25056: An issue was discovered on Samsung mobile devices with Q(10.0) (Galaxy S20) software. Because HAL im
An issue was discovered on Samsung mobile devices with Q(10.0) (Galaxy S20) software. Because HAL improperly checks versions, bootloading by the S.LSI NFC chipset is mishandled. The Samsung ID is SVE-2020-16169 (August 2020).
nvd
CVE-2019-20608P4HIGHCVSS 7.5v7.0v7.1.0+5 more2020-03-24
CVE-2019-20608 [HIGH] CVE-2019-20608: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. An attac
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. An attacker can use Emergency mode to disable features. The Samsung IDs are SVE-2018-13164, SVE-2018-13165 (April 2019).
nvd
CVE-2017-18668P4HIGHCVSS 7.5v6.02020-04-07
CVE-2017-18668 [HIGH] CWE-276 CVE-2017-18668: An issue was discovered on Samsung mobile devices with M(6.0) software. Attackers can prevent users
An issue was discovered on Samsung mobile devices with M(6.0) software. Attackers can prevent users from making outbound calls and sending outbound text messages. The Samsung ID is SVE-2017-8706 (June 2017).
nvd
CVE-2026-0148P3UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0148 CVE-2026-0148: In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due
In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0164P3UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0164 CVE-2026-0164: In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0160P3UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0160 CVE-2026-0160: In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out o
In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-25410P4HIGHCVSS 7.1v11.02021-06-11
CVE-2021-25410 [HIGH] CWE-20 CVE-2021-25410: Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows loca
Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an escalated privilege.
nvd
CVE-2022-22264P4HIGHCVSS 7.1v10.0v11.0+1 more2022-01-10
CVE-2022-22264 [HIGH] CWE-20 CVE-2022-22264: Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local a
Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files without permission.
nvd
CVE-2015-3879P4CRITICALCVSS 9.3≤ 5.12015-10-06
CVE-2015-3879 [CRITICAL] CWE-264 CVE-2015-3879: Media Player Framework in Android before 5.1.1 LMY48T allows attackers to gain privileges via a craf
Media Player Framework in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bug 23223325.
nvd
CVE-2021-30162P4HIGHCVSS 7.1v4.4v4.4.1+20 more2021-04-06
CVE-2021-30162 [HIGH] CVE-2021-30162: An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can
An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can leverage ISMS services to bypass access control on specific content providers. The LG ID is LVE-SMP-210003 (April 2021).
nvd
CVE-2014-7953P4HIGHCVSS 7.0v4.4.42017-07-07
CVE-2014-7953 [HIGH] CWE-362 CVE-2014-7953: Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows l
Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by running "pm install" with the target apk, and simultaneously running a crafted script to process logcat's output looking for a dexopt line, which once found shoul
nvd
CVE-2021-0476P4HIGHCVSS 7.0v9.0v10.0+2 more2021-06-11
CVE-2021-0476 [HIGH] CWE-362 CVE-2021-0476: In FindOrCreatePeer of btif_av.cc, there is a possible use after free due to a race condition. This
In FindOrCreatePeer of btif_av.cc, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-169252501
nvd
CVE-2021-0508P4HIGHCVSS 7.0v8.1v9.0+3 more2021-06-21
CVE-2021-0508 [HIGH] CWE-362 CVE-2021-0508: In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. T
In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-176444154
nvd
CVE-2021-0520P4HIGHCVSS 7.0v10.0v11.0+1 more2021-06-21
CVE-2021-0520 [HIGH] CWE-362 CVE-2021-0520: In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free d
In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-176237595
nvd
CVE-2021-0509P4HIGHCVSS 7.0v8.1v9.0+3 more2021-06-21
CVE-2021-0509 [HIGH] CWE-362 CVE-2021-0509: In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition
In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-176444161
nvd