Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 18 of 339
CVE-2025-36896P3CRITICALCVSS 9.8vAndroid kernel2025-09-04
CVE-2025-36896 [CRITICAL] CWE-269 CVE-2025-36896: WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-39476
WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.
nvd
CVE-2017-13230P3HIGHCVSS 8.8v5.1.1v6.0+6 more2018-02-12
CVE-2017-13230 [HIGH] CWE-787 CVE-2017-13230: In hevc codec, there is an out-of-bounds write due to an incorrect bounds check with the i2_pic_widt
In hevc codec, there is an out-of-bounds write due to an incorrect bounds check with the i2_pic_width_in_luma_samples value. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65483665.
nvd
CVE-2019-2027P3HIGHCVSS 8.8v7.0v7.1.1+4 more2019-04-19
CVE-2019-2027 [HIGH] CWE-787 CVE-2019-2027: In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds c
In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID:
nvd
CVE-2019-2109P3HIGHCVSS 8.8v7.0v7.1.1+4 more2019-07-08
CVE-2019-2109 [HIGH] CWE-787 CVE-2019-2109: In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due
In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1.
nvd
CVE-2019-2206P3HIGHCVSS 8.8v8.0v8.1+3 more2019-11-13
CVE-2019-2206 [HIGH] CWE-787 CVE-2019-2206: In rw_i93_sm_set_read_only of rw_i93.cc, there is a possible out of bounds write due to a missing bo
In rw_i93_sm_set_read_only of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-139188579
nvd
CVE-2019-2106P3HIGHCVSS 8.8v7.0v7.1.1+5 more2019-07-08
CVE-2019-2106 [HIGH] CWE-787 CVE-2019-2106: In ihevcd_sao_shift_ctb of ihevcd_sao.c, there is a possible out of bounds write due to a missing bo
In ihevcd_sao_shift_ctb of ihevcd_sao.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Androi
nvd
CVE-2019-2044P3HIGHCVSS 8.8v7.0v7.1.1+5 more2019-05-08
CVE-2019-2044 [HIGH] CWE-787 CVE-2019-2044: In MakeMP>G4VideoCodecSpecificData of APacketSource.cpp, there is a possible out-of-bounds write due
In MakeMP>G4VideoCodecSpecificData of APacketSource.cpp, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 And
nvd
CVE-2024-27207P3CRITICALCVSS 9.1v13.0v132024-03-11
CVE-2024-27207 [CRITICAL] CWE-269 CVE-2024-27207: Exported broadcast receivers allowing malicious apps to bypass broadcast protection.
Exported broadcast receivers allowing malicious apps to bypass broadcast protection.
nvd
CVE-2021-0475P3HIGHCVSS 8.8v10.0v11.0+1 more2021-06-11
CVE-2021-0475 [HIGH] CWE-416 CVE-2021-0475: In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after f
In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-175686168
nvd
CVE-2018-9504P3HIGHCVSS 8.8v7.0v7.1.1+4 more2018-10-02
CVE-2018-9504 [HIGH] CWE-787 CVE-2018-9504: In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds write due to an incorrec
In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android
nvd
CVE-2020-0321P3HIGHCVSS 8.8v11.0vAndroid-112020-09-17
CVE-2020-0321 [HIGH] CWE-787 CVE-2020-0321: In the mp3 extractor, there is a possible out of bounds write due to uninitialized data. This could
In the mp3 extractor, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155171907
nvd
CVE-2017-13255P3HIGHCVSS 8.8v5.1.1v6.0+6 more2018-04-04
CVE-2017-13255 [HIGH] CWE-787 CVE-2017-13255: In process_service_attr_req of sdp_server.c, there is an out of bounds write due to a missing bounds
In process_service_attr_req of sdp_server.c, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68776054.
nvd
CVE-2019-2009P3HIGHCVSS 8.8v7.0v7.1.1+5 more2019-06-19
CVE-2019-2009 [HIGH] CWE-787 CVE-2019-2009: In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds c
In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android
nvd
CVE-2011-1352P4MEDIUMCVSS 6.9PoC≤ 2.3.5v1.0+15 more2013-02-05
CVE-2011-1352 [MEDIUM] CWE-119 CVE-2011-1352: The PowerVR SGX driver in Android before 2.3.6 allows attackers to gain root privileges via an appli
The PowerVR SGX driver in Android before 2.3.6 allows attackers to gain root privileges via an application that triggers kernel memory corruption using crafted user data to the pvrsrvkm device.
nvd
CVE-2023-21127P3HIGHCVSS 8.8v11.0v12.0+3 more2023-06-15
CVE-2023-21127 [HIGH] CWE-908 CVE-2023-21127: In readSampleData of NuMediaExtractor.cpp, there is a possible out of bounds write due to uninitiali
In readSampleData of NuMediaExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-275418191
nvd
CVE-2023-21108P3HIGHCVSS 8.8v11.0v12.0+3 more2023-06-15
CVE-2023-21108 [HIGH] CWE-416 CVE-2023-21108: In sdpu_build_uuid_seq of sdp_discovery.cc, there is a possible out of bounds write due to a use aft
In sdpu_build_uuid_seq of sdp_discovery.cc, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Andr
nvd
CVE-2024-47014P3HIGHCVSS 8.8vAndroid kernel2024-10-25
CVE-2024-47014 [HIGH] CWE-276 CVE-2024-47014: Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component,
Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292.
nvd
CVE-2023-35673P3HIGHCVSS 8.8v11.0v12.0+6 more2023-09-11
CVE-2023-35673 [HIGH] CWE-190 CVE-2023-35673: In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an integer ove
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35658P3HIGHCVSS 8.8v11.0v12.0+6 more2023-09-11
CVE-2023-35658 [HIGH] CWE-416 CVE-2023-35658: In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible privilege escalation due to a use
In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible privilege escalation due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20040P3HIGHCVSS 8.8v12.0v13.0+1 more2024-04-01
CVE-2024-20040 [HIGH] CWE-787 CVE-2024-20040: In wlan firmware, there is a possible out of bounds write due to improper input validation. This cou
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08360153 (for MT6XXX chipsets) / WCNCR00363530 (for MT79XX chipsets); Issue ID: MSV-979.
nvd