Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 162 of 339
CVE-2017-0616P4HIGHCVSS 7.0≤ 7.1.22017-05-12
CVE-2017-0616 [HIGH] CVE-2017-0616: An elevation of privilege vulnerability in the MediaTek system management interrupt driver could ena
An elevation of privilege vulnerability in the MediaTek system management interrupt driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-34470286. References: M-ALPS03149
nvd
CVE-2015-6596P4CRITICALCVSS 9.3≤ 5.12015-10-06
CVE-2015-6596 [CRITICAL] CWE-264 CVE-2015-6596: mediaserver in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted applica
mediaserver in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bugs 20731946 and 20719651, a different vulnerability than CVE-2015-7717.
nvd
CVE-2018-9539P4HIGHCVSS 7.0v8.0v8.1+1 more2018-11-14
CVE-2018-9539 [HIGH] CWE-362 CVE-2018-9539: In the ClearKey CAS descrambler, there is a possible use after free due to a race condition. This co
In the ClearKey CAS descrambler, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-113027383
nvd
CVE-2022-28783P4HIGHCVSS 7.1v10.0v11.0+1 more2022-05-03
CVE-2022-28783 [HIGH] CWE-20 CVE-2022-28783: Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows
Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.
nvd
CVE-2025-48537P4HIGHCVSS 7.1v13.0v14.0+6 more2025-09-04
CVE-2025-48537 [HIGH] CWE-20 CVE-2025-48537: In multiple locations, there is a possible way to persistently DoS the device due to improper input
In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-10200P4HIGHCVSS 7.0≤ 7.1.12017-03-07
CVE-2016-10200 [HIGH] CWE-264 CVE-2016-10200: Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local
Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.
nvd
CVE-2020-0218P4HIGHCVSS 7.0v10.0vAndroid-102020-06-11
CVE-2020-0218 [HIGH] CWE-362 CVE-2020-0218: In loadSoundModel and related functions of SoundTriggerHwService.cpp, there is possible out of bound
In loadSoundModel and related functions of SoundTriggerHwService.cpp, there is possible out of bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-136005905
nvd
CVE-2021-0688P4HIGHCVSS 7.0v8.1v9.0+3 more2021-10-06
CVE-2021-0688 [HIGH] CWE-362 CVE-2021-0688: In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race conditio
In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-161149543
nvd
CVE-2021-0482P4HIGHCVSS 7.0v11.0vAndroid-112021-06-11
CVE-2021-0482 [HIGH] CWE-416 CVE-2021-0482: In BinderDiedCallback of MediaCodec.cpp, there is a possible memory corruption due to a use after fr
In BinderDiedCallback of MediaCodec.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173791720
nvd
CVE-2022-20006P4HIGHCVSS 7.0v10.0v11.0+3 more2022-05-10
CVE-2022-20006 [HIGH] CWE-362 CVE-2022-20006: In several functions of KeyguardServiceWrapper.java and related files,, there is a possible way to b
In several functions of KeyguardServiceWrapper.java and related files,, there is a possible way to briefly view what's under the lockscreen due to a race condition. This could lead to local escalation of privilege if a Guest user is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Androi
nvd
CVE-2020-0238P4HIGHCVSS 7.0v8.0v8.1+3 more2020-08-11
CVE-2020-0238 [HIGH] CWE-367 CVE-2020-0238: In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attac
In updatePreferenceIntents of AccountTypePreferenceLoader, there is a possible confused deputy attack due to a race condition. This could lead to local escalation of privilege and launching privileged activities with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9
nvd
CVE-2019-2121P4HIGHCVSS 7.0v9.0vAndroid-92019-08-20
CVE-2019-2121 [HIGH] CWE-362 CVE-2019-2121: In ActivityManagerService.attachApplication of ActivityManagerService, there is a possible race cond
In ActivityManagerService.attachApplication of ActivityManagerService, there is a possible race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-131105245.
nvd
CVE-2023-32832P4HIGHCVSS 7.0v12.0v13.02023-11-06
CVE-2023-32832 [HIGH] CWE-787 CVE-2023-32832: In video, there is a possible memory corruption due to a race condition. This could lead to local es
In video, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08235273; Issue ID: ALPS08235273.
nvd
CVE-2020-0474P4HIGHCVSS 7.0v11.0vAndroid-112020-12-15
CVE-2020-0474 [HIGH] CWE-362 CVE-2020-0474: In HalCamera::requestNewFrame of HalCamera.cpp, there is a possible use-after-free due to a race con
In HalCamera::requestNewFrame of HalCamera.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169282240
nvd
CVE-2021-0565P4HIGHCVSS 7.0v11.0vAndroid-112021-06-22
CVE-2021-0565 [HIGH] CWE-362 CVE-2021-0565: In wrapUserThread of AudioStream.cpp, there is a possible use after free due to a race condition. Th
In wrapUserThread of AudioStream.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174801970
nvd
CVE-2022-20344P4HIGHCVSS 7.0v10.0v11.0+3 more2022-08-10
CVE-2022-20344 [HIGH] CWE-362 CVE-2022-20344: In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communi
In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroi
nvd
CVE-2025-20671P4HIGHCVSS 7.0v14.0v15.02025-05-05
CVE-2025-20671 [HIGH] CWE-787 CVE-2025-20671: In thermal, there is a possible out of bounds write due to a race condition. This could lead to loca
In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09698599; Issue ID: MSV-3228.
nvd
CVE-2021-0955P4HIGHCVSS 7.0v11.0vAndroid-112021-12-15
CVE-2021-0955 [HIGH] CWE-362 CVE-2021-0955: In pf_write_buf of FuseDaemon.cpp, there is possible memory corruption due to a race condition. This
In pf_write_buf of FuseDaemon.cpp, there is possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-192085766
nvd
CVE-2020-0182P4MEDIUMCVSS 6.5v10.0vAndroid-102020-06-11
CVE-2020-0182 [MEDIUM] CWE-125 CVE-2020-0182: In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bou
In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147140917
nvd
CVE-2020-0414P4MEDIUMCVSS 6.5v10.0v11.0+1 more2020-10-14
CVE-2020-0414 [MEDIUM] CWE-404 CVE-2020-0414: In AudioFlinger::RecordThread::threadLoop of audioflinger/Threads.cpp, there is a possible non-silen
In AudioFlinger::RecordThread::threadLoop of audioflinger/Threads.cpp, there is a possible non-silenced audio buffer due to a permissions bypass. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-15770
nvd