Google Android vulnerabilities
7,234 known vulnerabilities affecting google/android.
Total CVEs
7,234
CISA KEV
18
actively exploited
Public exploits
52
Exploited in wild
18
Severity breakdown
CRITICAL544HIGH2984MEDIUM3458LOW248
Vulnerabilities
Page 17 of 362
CVE-2025-48534HIGHCVSS 8.8v13.0v14.0+4 more2025-09-04
CVE-2025-48534 [HIGH] CWE-693 CVE-2025-48534: In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privileg
In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-48563HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48563 [HIGH] CWE-453 CVE-2025-48563: In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an
In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-48549HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-48549 [HIGH] CWE-862 CVE-2025-48549: In multiple locations, there is a possible way to record audio via a background app due to a missing
In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-26435HIGHCVSS 7.8v15.0v152025-09-04
CVE-2025-26435 [HIGH] CWE-269 CVE-2025-26435: In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a se
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-48553HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48553 [HIGH] CVE-2025-48553: In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device adm
In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device admin due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-32324HIGHCVSS 7.8v15.0v16.0+2 more2025-09-04
CVE-2025-32324 [HIGH] CWE-441 CVE-2025-32324: In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due
In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-36899HIGHCVSS 8.4vAndroid kernel2025-09-04
CVE-2025-36899 [HIGH] CWE-489 CVE-2025-36899: There is a possible escalation of privilege due to test/debugging code left in a production build. T
There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-48558HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48558 [HIGH] CWE-927 CVE-2025-48558: In multiple functions of BatteryService.java, there is a possible way to hijack implicit intent inte
In multiple functions of BatteryService.java, there is a possible way to hijack implicit intent intended for system app due to Implicit intent hijacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-48546HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48546 [HIGH] CWE-693 CVE-2025-48546: In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due
In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-26431HIGHCVSS 7.8v14.0v142025-09-04
CVE-2025-26431 [HIGH] CWE-693 CVE-2025-26431: In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enab
In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-32326HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-32326 [HIGH] CWE-441 CVE-2025-32326: In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent secu
In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
cvelistv5nvd
CVE-2025-0089HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-0089 [HIGH] CWE-693 CVE-2025-0089: In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in th
In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2024-56190HIGHCVSS 7.8vAndroid kernel2025-09-04
CVE-2024-56190 [HIGH] CWE-20 CVE-2024-56190: In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper
In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-48581HIGHCVSS 8.4v16.0v162025-09-04
CVE-2025-48581 [HIGH] CWE-754 CVE-2025-48581: In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to
In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-32333HIGHCVSS 7.8v14.0v142025-09-04
CVE-2025-32333 [HIGH] CWE-863 CVE-2025-32333: In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to
In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-26438HIGHCVSS 8.8v13.0v14.0+4 more2025-09-04
CVE-2025-26438 [HIGH] CWE-287 CVE-2025-26438: In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authe
In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-48527MEDIUMCVSS 6.2v13.0v14.0+6 more2025-09-04
CVE-2025-48527 [MEDIUM] CWE-200 CVE-2025-48527: In multiple locations, there is a possible way to leak hidden work profile notifications due to a lo
In multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-48538MEDIUMCVSS 5.5v13.0v14.0+6 more2025-09-04
CVE-2025-48538 [MEDIUM] CWE-20 CVE-2025-48538: In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide
In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2024-49739MEDIUMCVSS 4.0vAndroid SoC2025-09-04
CVE-2024-49739 [MEDIUM] CWE-787 CVE-2024-49739: In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation
In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd
CVE-2025-32330MEDIUMCVSS 5.7v13.0v14.0+4 more2025-09-04
CVE-2025-32330 [MEDIUM] CWE-1188 CVE-2025-32330: In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept th
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio stream due to an insecure default value. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5nvd