Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 204 of 339
CVE-2021-0504P4MEDIUMCVSS 6.5v11.0vAndroid-112021-06-21
CVE-2021-0504 [MEDIUM] CWE-125 CVE-2021-0504: In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing
In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179162665
nvd
CVE-2022-20221P4MEDIUMCVSS 6.5v10.0v11.0+3 more2022-07-13
CVE-2022-20221 [MEDIUM] CWE-125 CVE-2022-20221: In avrc_ctrl_pars_vendor_cmd of avrc_pars_ct.cc, there is a possible out of bounds read due to impro
In avrc_ctrl_pars_vendor_cmd of avrc_pars_ct.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12
nvd
CVE-2021-39805P4MEDIUMCVSS 6.5v12.0v12.1+1 more2022-04-12
CVE-2021-39805 [MEDIUM] CWE-125 CVE-2021-39805: In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bou
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure through Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-212694559
nvd
CVE-2021-25514P4MEDIUMCVSS 6.5v10.0v11.02021-12-08
CVE-2021-25514 [MEDIUM] CVE-2021-25514: An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to
An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information.
nvd
CVE-2022-20273P4MEDIUMCVSS 6.5v13.0vAndroid-132022-08-12
CVE-2022-20273 [MEDIUM] CWE-787 CVE-2022-20273: In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead
In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-206478022
nvd
CVE-2023-21395P4MEDIUMCVSS 6.5fixed in 14.0v142023-10-30
CVE-2023-21395 [MEDIUM] CWE-416 CVE-2023-21395: In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to rem
In Bluetooth, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9483P4MEDIUMCVSS 6.5v7.0v7.1.1+9 more2024-11-20
CVE-2018-9483 [MEDIUM] CWE-416 CVE-2018-9483: In bta_dm_remove_sec_dev_entry of bta_dm_act.cc, there is a possible out of bounds read due to a use
In bta_dm_remove_sec_dev_entry of bta_dm_act.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9486P4MEDIUMCVSS 6.5v7.0v7.1.1+9 more2024-11-20
CVE-2018-9486 [MEDIUM] CWE-125 CVE-2018-9486: In hidh_l2cif_data_ind of hidh_conn.cc, there is a possible out of bounds read due to a missing boun
In hidh_l2cif_data_ind of hidh_conn.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9371P4MEDIUMCVSS 6.4vSoCVersion2024-11-19
CVE-2018-9371 [MEDIUM] CWE-125 CVE-2018-9371: In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that
In the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mapping with insufficient blacklisting/whitelisting. This could lead to local elevation of privilege, given physical access to the device with no additional execution privileges needed. User interaction is needed for
nvd
CVE-2023-35645P4MEDIUMCVSS 6.4vAndroid kernel2023-10-11
CVE-2023-35645 [MEDIUM] CWE-362 CVE-2023-35645: In tbd of tbd, there is a possible memory corruption due to a race condition. This could lead to loc
In tbd of tbd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-20438P4MEDIUMCVSS 6.4v15.02026-03-02
CVE-2026-20438 [MEDIUM] CWE-367 CVE-2026-20438: In MAE, there is a possible out of bounds write due to a race condition. This could lead to local es
In MAE, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431920; Issue ID: MSV-5835.
nvd
CVE-2024-20055P4MEDIUMCVSS 6.3v12.0v13.02024-04-01
CVE-2024-20055 [MEDIUM] CWE-125 CVE-2024-20055: In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead
In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.
nvd
CVE-2025-0086P4MEDIUMCVSS 6.2v12.0v12.1+8 more2025-08-26
CVE-2025-0086 [MEDIUM] CWE-862 CVE-2025-0086: In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a
In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-25984P4MEDIUMCVSS 6.2v13.0v132024-03-11
CVE-2024-25984 [MEDIUM] CWE-120 CVE-2024-25984: In dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer
In dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0055P4MEDIUMCVSS 6.2v14.0v15.0+8 more2026-06-01
CVE-2026-0055 [MEDIUM] CWE-22 CVE-2026-0055: In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Pol
In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0046P4MEDIUMCVSS 6.2v14.0v15.0+4 more2026-06-01
CVE-2026-0046 [MEDIUM] CWE-269 CVE-2026-0046: In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a perm
In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-6709P4MEDIUMCVSS 5.9≥ 6.0, ≤ 6.0.1v7.02016-11-25
CVE-2016-6709 [MEDIUM] CWE-200 CVE-2016-6709: An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01
An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-the-middle attacker to gain access to sensitive information if a non-standard cipher suite is used by an application. This issue is rated as High because it could be used to access data without permission.
nvd
CVE-2023-52534P4MEDIUMCVSS 5.9v12.0v13.0+1 more2024-04-08
CVE-2023-52534 [MEDIUM] CWE-754 CVE-2023-52534: In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to
In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed
nvd
CVE-2023-44216P4MEDIUMCVSS 5.3v13.02023-09-27
CVE-2023-44216 [MEDIUM] CWE-203 CVE-2023-44216: PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transpar
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one ori
nvd
CVE-2023-52343P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-04-08
CVE-2023-52343 [MEDIUM] CWE-1284 CVE-2023-52343: In SecurityCommand message after as security has been actived., there is a possible improper input v
In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information disclosure no additional execution privileges needed
nvd