Google Android vulnerabilities
9,646 known vulnerabilities affecting google/android.
Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2
Vulnerabilities
Page 159 of 483
CVE-2022-25725HIGHCVSS 6.22023-01-01
CVE-2022-25725 [MEDIUM] CVE-2022-25725: Closed-source component
Android Security Bulletin 2023-01-01
CVE: CVE-2022-25725
Severity: HIGH
Component: Closed-source component
References: A-238101314
*
android
CVE-2022-33285HIGHCVSS 7.52023-01-01
CVE-2022-33285 [HIGH] CVE-2022-33285: Closed-source component
Android Security Bulletin 2023-01-01
CVE: CVE-2022-33285
Severity: HIGH
Component: Closed-source component
References: A-250627435
*
android
CVE-2022-33283HIGHCVSS 8.22023-01-01
CVE-2022-33283 [HIGH] CVE-2022-33283: Closed-source component
Android Security Bulletin 2023-01-01
CVE: CVE-2022-33283
Severity: HIGH
Component: Closed-source component
References: A-250627602
*
android
CVE-2022-20545HIGHCVSS 7.5v13.0vAndroid-132022-12-16
CVE-2022-20545 [HIGH] CWE-20 CVE-2022-20545: In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to
In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-239368697
nvd
CVE-2022-20503HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20503 [HIGH] CWE-862 CVE-2022-20503: In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a W
In onCreate of WifiDppConfiguratorActivity.java, there is a possible way for a guest user to add a WiFi configuration due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-22477
nvd
CVE-2022-20550HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20550 [HIGH] CWE-610 CVE-2022-20550: In Multiple Locations, there is a possibility to launch arbitrary protected activities due to a conf
In Multiple Locations, there is a possibility to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-242845514
nvd
CVE-2022-20516HIGHCVSS 7.5v13.0vAndroid-132022-12-16
CVE-2022-20516 [HIGH] CWE-191 CVE-2022-20516: In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an i
In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224002331
nvd
CVE-2022-20507HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20507 [HIGH] CWE-20 CVE-2022-20507: In onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary
In onMulticastListUpdateNotificationReceived of UwbEventManager.java, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246649179
nvd
CVE-2022-20540HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20540 [HIGH] CWE-416 CVE-2022-20540: In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a
In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-237291506
nvd
CVE-2022-20522HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20522 [HIGH] CWE-862 CVE-2022-20522: In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to loca
In getSlice of ProviderModelSlice.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-227470877
nvd
CVE-2022-20506HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20506 [HIGH] CWE-862 CVE-2022-20506: In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to loca
In onCreate of WifiDialogActivity.java, there is a missing permission check. This could lead to local escalation of privilege from a guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-226133034
nvd
CVE-2022-20520HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20520 [HIGH] CWE-1021 CVE-2022-20520: In onCreate of various files, there is a possible tapjacking/overlay attack. This could lead to loca
In onCreate of various files, there is a possible tapjacking/overlay attack. This could lead to local escalation of privilege or denial of server with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-227203202
nvd
CVE-2022-20512HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20512 [HIGH] CWE-20 CVE-2022-20512: In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched
In navigateUpTo of Task.java, there is a possible way to launch an intent handler with a mismatched intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238602879
nvd
CVE-2022-20524HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20524 [HIGH] CWE-416 CVE-2022-20524: In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. Th
In compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-228523213
nvd
CVE-2022-42544HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-42544 [HIGH] CWE-74 CVE-2022-42544: In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network
In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network add requests due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224545390
nvd
CVE-2022-20548HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20548 [HIGH] CWE-787 CVE-2022-20548: In setParameter of EqualizerEffect.cpp, there is a possible out of bounds write due to improper inpu
In setParameter of EqualizerEffect.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-240919398
nvd
CVE-2022-20547HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20547 [HIGH] CWE-862 CVE-2022-20547: In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state
In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-240301753
nvd
CVE-2022-20508HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20508 [HIGH] CWE-862 CVE-2022-20508: In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi s
In onAttach of ConfigureWifiSettings.java, there is a possible way for a guest user to change WiFi settings due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-218679614
nvd
CVE-2022-20546MEDIUMCVSS 6.7v13.0vAndroid-132022-12-16
CVE-2022-20546 [MEDIUM] CWE-787 CVE-2022-20546: In getCurrentConfigImpl of Effect.cpp, there is a possible out of bounds write due to a missing boun
In getCurrentConfigImpl of Effect.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-240266798
nvd
CVE-2022-20511MEDIUMCVSS 5.5v13.0vAndroid-132022-12-16
CVE-2022-20511 [MEDIUM] CWE-862 CVE-2022-20511: In getNearbyAppStreamingPolicy of DevicePolicyManagerService.java, there is a missing permission che
In getNearbyAppStreamingPolicy of DevicePolicyManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-235821829
nvd