cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 214 of 339
CVE-2022-33727P4MEDIUMCVSS 6.1v10.0v11.0+1 more2022-08-05
CVE-2022-33727 [MEDIUM] CWE-1021 CVE-2022-33727: A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attac A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
nvd
CVE-2021-25389P4MEDIUMCVSS 6.1v9.02021-06-11
CVE-2021-25389 [MEDIUM] CWE-287 CVE-2021-25389: Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use lock Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.
nvd
CVE-2025-20658P4MEDIUMCVSS 6.0v12.0v13.0+2 more2025-04-07
CVE-2025-20658 [MEDIUM] CWE-787 CVE-2025-20658: In DA, there is a possible permission bypass due to a logic error. This could lead to local escalati In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09474894; Issue ID: MSV-2597.
nvd
CVE-2022-23426P4MEDIUMCVSS 6.0v10.0v11.02022-02-11
CVE-2022-23426 [MEDIUM] CWE-94 CVE-2022-23426: A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allow A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.
nvd
CVE-2016-0818P4MEDIUMCVSS 5.9v4.0v4.0.1+22 more2016-03-12
CVE-2016-0818 [MEDIUM] CWE-254 CVE-2016-0818: The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in And The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trusted root CA, which allows man-in-the-middle attackers to spoof servers by leveraging access to an intermediate CA t
nvdosv
CVE-2024-20060P4MEDIUMCVSS 5.9v12.0v13.0+1 more2024-05-06
CVE-2024-20060 [MEDIUM] CWE-1332 CVE-2024-20060: In da, there is a possible escalation of privilege due to an incorrect status check. This could lead In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541754.
nvd
CVE-2024-27231P4MEDIUMCVSS 5.9vAndroid kernel2024-04-05
CVE-2024-27231 [MEDIUM] CWE-125 CVE-2024-27231: In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. In tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27234P4MEDIUMCVSS 5.9v13.0v132024-03-11
CVE-2024-27234 [MEDIUM] CWE-125 CVE-2024-27234: In fvp_set_target of fvp.c, there is a possible out of bounds read due to a missing bounds check. Th In fvp_set_target of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-25989P4MEDIUMCVSS 5.9v13.0v132024-03-11
CVE-2024-25989 [MEDIUM] CWE-125 CVE-2024-25989: In gpu_slc_liveness_update of pixel_gpu_slc.c, there is a possible out of bounds read due to a missi In gpu_slc_liveness_update of pixel_gpu_slc.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9493P4MEDIUMCVSS 5.5v7.0v7.1.1+4 more2018-10-02
CVE-2018-9493 [MEDIUM] CWE-89 CVE-2018-9493: In the content provider of the download manager, there is a possible SQL injection due to improper i In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 A
nvd
CVE-2020-0119P4MEDIUMCVSS 5.3v10.0vAndroid-102020-06-10
CVE-2020-0119 [MEDIUM] CWE-295 CVE-2020-0119: In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible m In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID:
nvd
CVE-2022-22271P4MEDIUMCVSS 5.5v9.0v10.0+1 more2022-01-10
CVE-2022-22271 [MEDIUM] CWE-125 CVE-2022-22271: A missing input validation before memory copy in TIMA trustlet prior to SMR Jan-2022 Release 1 allow A missing input validation before memory copy in TIMA trustlet prior to SMR Jan-2022 Release 1 allows attackers to copy data from arbitrary memory.
nvd
CVE-2024-0022P4MEDIUMCVSS 5.5v13.0v14.0+2 more2024-05-07
CVE-2024-0022 [MEDIUM] CWE-20 CVE-2024-0022: In multiple functions of CompanionDeviceManagerService.java, there is a possible launch Notification In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9406P4MEDIUMCVSS 5.5vAndroid Kernel2025-01-18
CVE-2018-9406 [MEDIUM] CWE-862 CVE-2018-9406: In NlpService, there is a possible way to obtain location information due to a missing permission ch In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-22263P4MEDIUMCVSS 5.5v11.02022-01-10
CVE-2022-22263 [MEDIUM] CWE-269 CVE-2022-22263: Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applica Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.
nvd
CVE-2025-48622P4MEDIUMCVSS 5.5v13.0v14.0+6 more2025-12-08
CVE-2025-48622 [MEDIUM] CWE-125 CVE-2025-48622: In ProcessArea of dng_misc_opcodes.cpp, there is a possible out of bounds read due to a buffer overf In ProcessArea of dng_misc_opcodes.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48591P4MEDIUMCVSS 5.5v13.0v14.0+4 more2025-12-08
CVE-2025-48591 [MEDIUM] CWE-862 CVE-2025-48591: In multiple locations, there is a possible way to read files from another user due to a missing perm In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48538P4MEDIUMCVSS 5.5v13.0v14.0+6 more2025-09-04
CVE-2025-48538 [MEDIUM] CWE-20 CVE-2025-48538: In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48604P4MEDIUMCVSS 5.5v13.0v14.0+6 more2025-12-08
CVE-2025-48604 [MEDIUM] CWE-862 CVE-2025-48604: In multiple locations, there is a possible way to read files from another user due to a missing perm In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47018P4MEDIUMCVSS 5.5vAndroid kernel2024-10-25
CVE-2024-47018 [MEDIUM] CWE-125 CVE-2024-47018: In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible out of bounds read due to a b In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase