Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 177 of 339
CVE-2026-20428P4MEDIUMCVSS 6.7v14.0v15.0+1 more2026-03-02
CVE-2026-20428 [MEDIUM] CWE-787 CVE-2026-20428: In display, there is a possible out of bounds write due to a missing bounds check. This could lead t
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5536.
nvd
CVE-2017-13311P4MEDIUMCVSS 6.7v7.0v7.1.1+7 more2024-11-15
CVE-2017-13311 [MEDIUM] CWE-276 CVE-2017-13311: In the read() function of ProcessStats.java, there is a possible read/write serialization issue lead
In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20784P4MEDIUMCVSS 6.7v14.0v15.0+1 more2026-01-06
CVE-2025-20784 [MEDIUM] CWE-457 CVE-2025-20784: In display, there is a possible memory corruption due to uninitialized data. This could lead to loca
In display, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182882; Issue ID: MSV-4683.
nvd
CVE-2019-9380P4MEDIUMCVSS 6.5v10.0vAndroid-102019-09-27
CVE-2019-9380 [MEDIUM] CWE-862 CVE-2019-9380: In the settings UI, there is a possible spoofing vulnerability due to a missing permission check. Th
In the settings UI, there is a possible spoofing vulnerability due to a missing permission check. This could lead to a user mistakenly changing permission settings with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-123700098
nvd
CVE-2021-39804P4MEDIUMCVSS 6.5v11.0v12.0+2 more2022-04-12
CVE-2021-39804 [MEDIUM] CWE-476 CVE-2021-39804: In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could
In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persistent denial of service in the file picker with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-215002587
nvd
CVE-2025-48598P4MEDIUMCVSS 6.6v16.0v162025-12-08
CVE-2025-48598 [MEDIUM] CWE-610 CVE-2025-48598: In multiple locations, there is a possible way to alter the primary user's face unlock settings due
In multiple locations, there is a possible way to alter the primary user's face unlock settings due to a confused deputy. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0045P4MEDIUMCVSS 6.5v12.0v12.1+6 more2024-03-11
CVE-2024-0045 [MEDIUM] CWE-125 CVE-2024-0045: In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input vali
In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9354P4MEDIUMCVSS 6.5v7.0v7.1.1+5 more2024-11-27
CVE-2018-9354 [MEDIUM] CWE-369 CVE-2018-9354: In VideoFrameScheduler.cpp of VideoFrameScheduler::PLL::fit, there is a possible remote denial of se
In VideoFrameScheduler.cpp of VideoFrameScheduler::PLL::fit, there is a possible remote denial of service due to divide by 0. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-24925P4MEDIUMCVSS 6.5v12.02022-02-11
CVE-2022-24925 [MEDIUM] CWE-20 CVE-2022-24925: Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged
Improper input validation vulnerability in SettingsProvider prior to Android S(12) allows privileged attackers to trigger a permanent denial of service attack on a victim's devices.
nvd
CVE-2018-9440P4MEDIUMCVSS 6.5v7.0v7.1.1+9 more2024-11-19
CVE-2018-9440 [MEDIUM] CVE-2018-9440: In parse of M3UParser.cpp there is a possible resource exhaustion due to improper input validation.
In parse of M3UParser.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2024-25990P4MEDIUMCVSS 6.4v13.0v132024-03-11
CVE-2024-25990 [MEDIUM] CWE-269 CVE-2024-25990: In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bound
In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-3855P4HIGHCVSS 7.8≤ 6.0.12016-08-06
CVE-2016-3855 [HIGH] CWE-125 CVE-2016-3855: drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not va
drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not validate a certain count parameter, which allows attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted application, aka Qualcomm internal bug CR990824.
nvd
CVE-2017-0728P4HIGHCVSS 7.8v5.0v5.0.1+10 more2017-08-09
CVE-2017-0728 [HIGH] CVE-2017-0728: A denial of service vulnerability in the Android media framework (hevc decoder). Product: Android. V
A denial of service vulnerability in the Android media framework (hevc decoder). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37469795.
nvd
CVE-2016-3849P4HIGHCVSS 7.8≤ 6.0.12016-08-05
CVE-2016-3849 [HIGH] CWE-264 CVE-2016-3849: The ION driver in Android before 2016-08-05 on Pixel C devices allows attackers to gain privileges v
The ION driver in Android before 2016-08-05 on Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 28939740.
nvd
CVE-2014-7916P4CRITICALCVSS 10.0≤ 4.4.42015-10-01
CVE-2014-7916 [CRITICAL] CWE-189 CVE-2014-7916: Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact
Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact and attack vectors, aka internal bug 15342751.
nvd
CVE-2014-7917P4CRITICALCVSS 10.0≤ 4.4.42015-10-01
CVE-2014-7917 [CRITICAL] CWE-189 CVE-2014-7917: Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact
Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact and attack vectors, aka internal bug 15342615.
nvd
CVE-2014-7915P4CRITICALCVSS 10.0≤ 4.4.42015-10-01
CVE-2014-7915 [CRITICAL] CWE-189 CVE-2014-7915: Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact
Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact and attack vectors, aka internal bug 15328708.
nvd
CVE-2016-6693P4CRITICALCVSS 9.8≤ 7.02016-10-10
CVE-2016-6693 [CRITICAL] CWE-20 CVE-2016-6693: sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via an invalid data length, aka Qualcomm internal bug CR 1027585.
nvd
CVE-2016-6694P4CRITICALCVSS 9.8≤ 7.02016-10-10
CVE-2016-6694 [CRITICAL] CWE-20 CVE-2016-6694: sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via crafted parameter data, aka Qualcomm internal bug CR 1033525.
nvd
CVE-2018-21091P4HIGHCVSS 7.5v6.0v6.0.1+4 more2020-04-08
CVE-2018-21091 [HIGH] CWE-755 CVE-2018-21091: An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. Telecom has a Sys
An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. Telecom has a System Crash via abnormal exception handling. The Samsung ID is SVE-2017-10906 (January 2018).
nvd