Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 201 of 339
CVE-2023-20749P4MEDIUMCVSS 6.7v13.02023-06-06
CVE-2023-20749 [MEDIUM] CWE-787 CVE-2023-20749: In swpm, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In swpm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780926; Issue ID: ALPS07780926.
nvd
CVE-2023-20628P4MEDIUMCVSS 6.7v12.0v13.02023-03-07
CVE-2023-20628 [MEDIUM] CWE-248 CVE-2023-20628: In thermal, there is a possible memory corruption due to an uncaught exception. This could lead to l
In thermal, there is a possible memory corruption due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494460; Issue ID: ALPS07494460.
nvd
CVE-2023-20626P4MEDIUMCVSS 6.7v10.0v11.0+1 more2023-03-07
CVE-2023-20626 [MEDIUM] CWE-20 CVE-2023-20626: In msdc, there is a possible out of bounds write due to an incorrect bounds check. This could lead t
In msdc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07405223; Issue ID: ALPS07405223.
nvd
CVE-2025-20698P4MEDIUMCVSS 6.7v13.0v14.0+1 more2025-08-04
CVE-2025-20698 [MEDIUM] CWE-787 CVE-2025-20698: In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead
In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09915400; Issue ID: MSV-3793.
nvd
CVE-2025-20697P4MEDIUMCVSS 6.7v14.0v15.02025-08-04
CVE-2025-20697 [MEDIUM] CWE-787 CVE-2025-20697: In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead
In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09915681; Issue ID: MSV-3795.
nvd
CVE-2024-20059P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-05-06
CVE-2024-20059 [MEDIUM] CWE-1332 CVE-2024-20059: In da, there is a possible escalation of privilege due to an incorrect status check. This could lead
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541749.
nvd
CVE-2024-20056P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-05-06
CVE-2024-20056 [MEDIUM] CWE-20 CVE-2024-20056: In preloader, there is a possible escalation of privilege due to an insecure default value. This cou
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185.
nvd
CVE-2024-20012P4MEDIUMCVSS 6.7v12.0v13.02024-02-05
CVE-2024-20012 [MEDIUM] CWE-843 CVE-2024-20012: In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to
In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358566; Issue ID: ALPS08358566.
nvd
CVE-2023-20837P4MEDIUMCVSS 6.7v12.0v13.02023-09-04
CVE-2023-20837 [MEDIUM] CWE-787 CVE-2023-20837: In seninf, there is a possible out of bounds write due to a missing bounds check. This could lead to
In seninf, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07992786; Issue ID: ALPS07992786.
nvd
CVE-2023-21116P4MEDIUMCVSS 6.7v11.0v12.0+3 more2023-05-15
CVE-2023-21116 [MEDIUM] CWE-863 CVE-2023-21116: In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade sys
In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Androi
nvd
CVE-2021-0897P4MEDIUMCVSS 6.7v10.0v11.0+1 more2021-12-17
CVE-2021-0897 [MEDIUM] CWE-367 CVE-2021-0897: In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to
In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05670549.
nvd
CVE-2023-20724P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-06-06
CVE-2023-20724 [MEDIUM] CWE-125 CVE-2023-20724: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07843845; Issue ID: ALPS07843841.
nvd
CVE-2023-20723P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-06-06
CVE-2023-20723 [MEDIUM] CWE-125 CVE-2023-20723: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07843845; Issue ID: ALPS07843845.
nvd
CVE-2023-20699P4MEDIUMCVSS 6.7v12.0v13.02023-05-15
CVE-2023-20699 [MEDIUM] CWE-787 CVE-2023-20699: In adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In adsp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07696073; Issue ID: ALPS07696073.
nvd
CVE-2023-32818P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-11-06
CVE-2023-32818 [MEDIUM] CWE-843 CVE-2023-32818: In vdec, there is a possible out of bounds write due to type confusion. This could lead to local esc
In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08163896 & ALPS08013430; Issue ID: ALPS07867715.
nvd
CVE-2023-32830P4MEDIUMCVSS 6.7v10.0v11.02023-10-02
CVE-2023-32830 [MEDIUM] CWE-787 CVE-2023-32830: In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to
In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03802522; Issue ID: DTV03802522.
nvd
CVE-2023-20804P4MEDIUMCVSS 6.7v12.0v13.02023-08-07
CVE-2023-20804 [MEDIUM] CWE-787 CVE-2023-20804: In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07199773; Issue ID: ALPS07326384.
nvd
CVE-2023-20795P4MEDIUMCVSS 6.7v12.0v13.02023-08-07
CVE-2023-20795 [MEDIUM] CWE-787 CVE-2023-20795: In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07864900; Issue ID: ALPS07864900.
nvd
CVE-2023-20807P4MEDIUMCVSS 6.7v12.0v13.02023-08-07
CVE-2023-20807 [MEDIUM] CWE-787 CVE-2023-20807: In dpe, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In dpe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608433; Issue ID: ALPS07608433.
nvd
CVE-2023-20786P4MEDIUMCVSS 6.7v12.0v13.02023-08-07
CVE-2023-20786 [MEDIUM] CWE-787 CVE-2023-20786: In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767811; Issue ID: ALPS07767811.
nvd