cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 219 of 339
CVE-2022-38697P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-10-14
CVE-2022-38697 [MEDIUM] CWE-862 CVE-2022-38697: In messaging service, there is a missing permission check. This could lead to access unexpected prov In messaging service, there is a missing permission check. This could lead to access unexpected provider in contacts service with no additional execution privileges needed.
nvd
CVE-2022-20351P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-10-11
CVE-2022-20351 [MEDIUM] CWE-89 CVE-2022-20351: In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to In queryInternal of CallLogProvider.java, there is a possible access to voicemail information due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-22477192
nvd
CVE-2025-48561P4MEDIUMCVSS 5.5v13.0v14.0+6 more2025-09-04
CVE-2025-48561 [MEDIUM] CWE-203 CVE-2025-48561: In multiple locations, there is a possible way to access data displayed on the screen due to side ch In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0375P4MEDIUMCVSS 5.5v11.0vAndroid-112021-03-10
CVE-2021-0375 [MEDIUM] CWE-330 CVE-2021-0375: In onPackageModified of VoiceInteractionManagerService.java, there is a possible change of default a In onPackageModified of VoiceInteractionManagerService.java, there is a possible change of default applications due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-167261484
nvd
CVE-2023-40092P4MEDIUMCVSS 5.5v11.0v12.0+8 more2023-12-04
CVE-2023-40092 [MEDIUM] CVE-2023-40092: In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40081P4MEDIUMCVSS 5.5v11.0v12.0+7 more2023-12-04
CVE-2023-40081 [MEDIUM] CVE-2023-40081: In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another us In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-33882P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-33882 [MEDIUM] CWE-862 CVE-2023-33882: In telephony service, there is a missing permission check. This could lead to local information disc In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2024-49722P4MEDIUMCVSS 5.5v15.0v152025-09-02
CVE-2024-49722 [MEDIUM] CWE-610 CVE-2024-49722: In showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due t In showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34721P4MEDIUMCVSS 5.5v12.0v12.1+6 more2024-07-09
CVE-2024-34721 [MEDIUM] CWE-922 CVE-2024-34721: In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20448P4MEDIUMCVSS 5.5v10.0v11.0+4 more2022-11-08
CVE-2022-20448 [MEDIUM] CWE-276 CVE-2022-20448: In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data acr In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-
nvd
CVE-2024-0020P4MEDIUMCVSS 5.5v11.0v12.0+8 more2024-02-16
CVE-2024-0020 [MEDIUM] CWE-200 CVE-2024-0020: In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35675P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-09-11
CVE-2023-35675 [MEDIUM] CVE-2023-35675: In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files played by another user on the same device due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21274P4MEDIUMCVSS 5.5v12.0v12.1+4 more2023-08-14
CVE-2023-21274 [MEDIUM] CWE-125 CVE-2023-21274: In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a miss In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21291P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-10-06
CVE-2023-21291 [MEDIUM] CWE-862 CVE-2023-21291: In visitUris of Notification.java, there is a possible way to reveal image contents from another use In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0706P4MEDIUMCVSS 5.5v10.0v11.0+1 more2021-10-22
CVE-2021-0706 [MEDIUM] CWE-862 CVE-2021-0706: In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app compon In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-193444889
nvd
CVE-2023-42715P4MEDIUMCVSS 5.5v11.0v12.02023-12-04
CVE-2023-42715 [MEDIUM] CWE-668 CVE-2023-42715: In telephony service, there is a possible missing permission check. This could lead to local informa In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2025-48600P4MEDIUMCVSS 5.5v15.0v16.0+4 more2025-12-08
CVE-2025-48600 [MEDIUM] CWE-862 CVE-2025-48600: In multiple files, there is a possible way to reveal information across users due to a missing permi In multiple files, there is a possible way to reveal information across users due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22421P4MEDIUMCVSS 5.5v13.0v14.0+4 more2025-09-02
CVE-2025-22421 [MEDIUM] CWE-209 CVE-2025-22421: In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification content leak through the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31312P4MEDIUMCVSS 5.5v12.0v12.1+6 more2024-07-09
CVE-2024-31312 [MEDIUM] CWE-276 CVE-2024-31312: In multiple locations, there is a possible information leak due to a missing permission check. This In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposing played media with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-48415P4MEDIUMCVSS 5.5vAndroid kernel2023-12-08
CVE-2023-48415 [MEDIUM] CWE-125 CVE-2023-48415: In Init of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds In Init of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase