cbcvebase.

Google Android vulnerabilities

9,713 known vulnerabilities affecting google/android.

Total CVEs
9,713
CISA KEV
49
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5220MEDIUM3343LOW265UNKNOWN2

Vulnerabilities

Page 22 of 486
CVE-2025-26440HIGHCVSS 7.8v14.0v142025-09-04
CVE-2025-26440 [HIGH] CWE-862 CVE-2025-26440: In multiple functions of CameraService.cpp, there is a possible way to use the camera from the backg In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-26454HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-26454 [HIGH] CWE-441 CVE-2025-26454: In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another user due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-22414HIGHCVSS 7.8v13.0v14.0+2 more2025-09-04
CVE-2025-22414 [HIGH] CWE-862 CVE-2025-22414: In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48546HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48546 [HIGH] CWE-693 CVE-2025-48546: In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-32312HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-32312 [HIGH] CWE-502 CVE-2025-32312: In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified data to be passed to the next process due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-48532HIGHCVSS 7.3v16.0v162025-09-04
CVE-2025-48532 [HIGH] CWE-441 CVE-2025-48532: In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_S In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvdandroid
CVE-2025-48552HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48552 [HIGH] CVE-2025-48552: In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from persistence due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-32324HIGHCVSS 7.8v15.0v16.0+2 more2025-09-04
CVE-2025-32324 [HIGH] CWE-441 CVE-2025-32324: In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-48549HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-48549 [HIGH] CWE-862 CVE-2025-48549: In multiple locations, there is a possible way to record audio via a background app due to a missing In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-36894HIGHCVSS 7.5vAndroid kernel2025-09-04
CVE-2025-36894 [HIGH] CWE-476 CVE-2025-36894: In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36899HIGHCVSS 8.4vAndroid kernel2025-09-04
CVE-2025-36899 [HIGH] CWE-489 CVE-2025-36899: There is a possible escalation of privilege due to test/debugging code left in a production build. T There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48558HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48558 [HIGH] CWE-927 CVE-2025-48558: In multiple functions of BatteryService.java, there is a possible way to hijack implicit intent inte In multiple functions of BatteryService.java, there is a possible way to hijack implicit intent intended for system app due to Implicit intent hijacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-48544HIGHCVSS 7.8v13.0v14.0+5 more2025-09-04
CVE-2025-48544 [HIGH] CWE-89 CVE-2025-48544: In multiple locations, there is a possible way to read files belonging to other apps due to SQL inje In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-26430HIGHCVSS 7.8v15.0v152025-09-04
CVE-2025-26430 [HIGH] CWE-285 CVE-2025-26430: In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-36906HIGHCVSS 7.8vAndroid kernel2025-09-04
CVE-2025-36906 [HIGH] CWE-122 CVE-2025-36906: In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26431HIGHCVSS 7.8v14.0v142025-09-04
CVE-2025-26431 [HIGH] CWE-693 CVE-2025-26431: In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enab In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48539HIGHCVSS 8.0v15.0v16.0+2 more2025-09-04
CVE-2025-48539 [HIGH] CWE-416 CVE-2025-48539: In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after fre In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-36903HIGHCVSS 7.8vAndroid kernel2025-09-04
CVE-2025-36903 [HIGH] CWE-787 CVE-2025-36903: In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This c In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48581HIGHCVSS 8.4v16.0v162025-09-04
CVE-2025-48581 [HIGH] CWE-754 CVE-2025-48581: In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-56190HIGHCVSS 7.8vAndroid kernel2025-09-04
CVE-2024-56190 [HIGH] CWE-20 CVE-2024-56190: In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd