cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 225 of 339
CVE-2025-26453P4MEDIUMCVSS 5.5v13.0v14.0+4 more2025-09-04
CVE-2025-26453 [MEDIUM] CWE-200 CVE-2025-26453: In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data le In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9435P4MEDIUMCVSS 5.5v6.0v6.0.1+8 more2024-12-02
CVE-2018-9435 [MEDIUM] CWE-125 CVE-2018-9435: In gatt_process_error_rsp of gatt_cl.cc, there is a possible out of bound read due to a missing boun In gatt_process_error_rsp of gatt_cl.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27235P4MEDIUMCVSS 5.5v13.0v132024-03-11
CVE-2024-27235 [MEDIUM] CWE-125 CVE-2024-27235: In plugin_extern_func of , there is a possible out of bounds read due to a missing bounds check. Thi In plugin_extern_func of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-42649P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-11-01
CVE-2023-42649 [MEDIUM] CVE-2023-42649: In engineermode, there is a possible missing permission check. This could lead to local information In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2025-36929P4MEDIUMCVSS 5.5vAndroid kernel2025-12-11
CVE-2025-36929 [MEDIUM] CWE-20 CVE-2025-36929: In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35664P4MEDIUMCVSS 5.5v12.0v12.1+4 more2023-09-11
CVE-2023-35664 [MEDIUM] CWE-125 CVE-2023-35664: In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a miss In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-30936P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-07-12
CVE-2023-30936 [MEDIUM] CWE-862 CVE-2023-30936: In telephony service, there is a missing permission check. This could lead to local information disc In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-40108P4MEDIUMCVSS 5.5v12.0v12.1+3 more2025-01-21
CVE-2023-40108 [MEDIUM] CWE-200 CVE-2023-40108: In multiple locations, there is a possible way to access media content belonging to another user due In multiple locations, there is a possible way to access media content belonging to another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40113P4MEDIUMCVSS 5.5v11.0v12.0+6 more2024-02-15
CVE-2023-40113 [MEDIUM] CWE-862 CVE-2023-40113: In multiple locations, there is a possible way for apps to access cross-user message data due to a m In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40105P4MEDIUMCVSS 5.5v11.0v12.0+8 more2024-02-15
CVE-2023-40105 [MEDIUM] CWE-862 CVE-2023-40105: In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21382P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21382 [MEDIUM] CWE-862 CVE-2023-21382: In Content Resolver, there is a possible method to access metadata about existing content providers In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21230P4MEDIUMCVSS 5.5v11.0v13.0+2 more2023-08-14
CVE-2023-21230 [MEDIUM] CWE-754 CVE-2023-21230: In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point change and its BSSID or SSID due to a precondition check failure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi
nvd
CVE-2018-9449P4MEDIUMCVSS 5.5v6.0v6.0.1+8 more2024-12-03
CVE-2018-9449 [MEDIUM] CWE-125 CVE-2018-9449: In process_service_search_attr_rsp of sdp_discovery.cc, there is a possible out of bound read due to In process_service_search_attr_rsp of sdp_discovery.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48529P4MEDIUMCVSS 5.5v13.0v14.0+6 more2025-09-04
CVE-2025-48529 [MEDIUM] CWE-441 CVE-2025-48529: In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is a possible cross user data le In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is a possible cross user data leak due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-42648P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-11-01
CVE-2023-42648 [MEDIUM] CWE-862 CVE-2023-42648: In engineermode, there is a possible missing permission check. This could lead to local information In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42637P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-11-01
CVE-2023-42637 [MEDIUM] CWE-862 CVE-2023-42637: In validationtools, there is a possible missing permission check. This could lead to local informati In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42634P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-11-01
CVE-2023-42634 [MEDIUM] CWE-862 CVE-2023-42634: In validationtools, there is a possible missing permission check. This could lead to local informati In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42635P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-11-01
CVE-2023-42635 [MEDIUM] CWE-862 CVE-2023-42635: In validationtools, there is a possible missing permission check. This could lead to local informati In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42640P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-11-01
CVE-2023-42640 [MEDIUM] CWE-862 CVE-2023-42640: In validationtools, there is a possible missing permission check. This could lead to local informati In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-42636P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-11-01
CVE-2023-42636 [MEDIUM] CWE-862 CVE-2023-42636: In validationtools, there is a possible missing permission check. This could lead to local informati In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
Google Android vulnerabilities | cvebase