cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 227 of 339
CVE-2022-20396P4MEDIUMCVSS 5.5v12.1v13.0+1 more2022-09-13
CVE-2022-20396 [MEDIUM] CWE-345 CVE-2022-20396: In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, with In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L And
nvd
CVE-2025-36893P4MEDIUMCVSS 5.5vAndroid kernel2025-09-04
CVE-2025-36893 [MEDIUM] CWE-908 CVE-2025-36893: In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitializ In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21234P4MEDIUMCVSS 5.5v11.0v13.0+2 more2023-08-14
CVE-2023-21234 [MEDIUM] CWE-862 CVE-2023-21234: In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable de In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47029P4MEDIUMCVSS 5.5vAndroid kernel2024-10-25
CVE-2024-47029 [MEDIUM] CWE-125 CVE-2024-47029: In TrustySharedMemoryManager::GetSharedMemory of ondevice/trusty/trusty_shared_memory_manager.cc, th In TrustySharedMemoryManager::GetSharedMemory of ondevice/trusty/trusty_shared_memory_manager.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47034P4MEDIUMCVSS 5.5vAndroid kernel2024-10-25
CVE-2024-47034 [MEDIUM] CWE-125 CVE-2024-47034: there is a possible out of bounds read due to a missing bounds check. This could lead to local infor there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47026P4MEDIUMCVSS 5.5vAndroid kernel2024-10-25
CVE-2024-47026 [MEDIUM] CWE-125 CVE-2024-47026: In gsc_gsa_rescue of gsc_gsa.c, there is a possible out of bounds read due to an incorrect bounds ch In gsc_gsa_rescue of gsc_gsa.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20942P4MEDIUMCVSS 5.5v12.0v12.1+4 more2023-07-13
CVE-2023-20942 [MEDIUM] CWE-326 CVE-2023-20942: In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying th In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-9323P4MEDIUMCVSS 5.3v10.0vAndroid-102019-09-27
CVE-2019-9323 [MEDIUM] CWE-862 CVE-2019-9323: In the Wallpaper Manager service, there is a possible information disclosure due to a missing permis In the Wallpaper Manager service, there is a possible information disclosure due to a missing permission check. Any application can access wallpaper image with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-30770233
nvd
CVE-2019-20532P4MEDIUMCVSS 5.3v8.0v8.1+2 more2020-03-24
CVE-2019-20532 [MEDIUM] CWE-306 CVE-2019-20532: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attacke An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can access the Developer options without authentication. The Samsung ID is SVE-2019-15800 (December 2019).
nvd
CVE-2021-1037P4MEDIUMCVSS 5.3v9.0v10.0+3 more2022-01-14
CVE-2021-1037 [MEDIUM] CWE-862 CVE-2021-1037: The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permissio The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for it. This lets apps keep track of what devices are paired without requesting BLUETOOTH permissions.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-162951906
nvd
CVE-2024-22006P4MEDIUMCVSS 5.3v13.0v132024-03-11
CVE-2024-22006 [MEDIUM] CWE-125 CVE-2024-22006: OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of th OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device.
nvd
CVE-2015-6613P4MEDIUMCVSS 5.1≥ 5.0, < 5.1.1v6.02015-11-03
CVE-2015-6613 [MEDIUM] CWE-77 CVE-2015-6613: Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port, and consequently gain privileges, via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24371736.
nvd
CVE-2021-25443P4MEDIUMCVSS 5.3v8.1v9.0+2 more2021-08-05
CVE-2021-25443 [MEDIUM] CWE-825 CVE-2021-25443: A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows maliciou A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attacker.
nvd
CVE-2026-20417P4MEDIUMCVSS 5.3v15.0v16.02026-02-02
CVE-2026-20417 [MEDIUM] CWE-787 CVE-2026-20417: In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to l In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10314946 / ALPS10340155; Issue ID: MSV-5154.
nvd
CVE-2023-32871P4MEDIUMCVSS 5.3v12.0v13.0+2 more2024-05-06
CVE-2023-32871 [MEDIUM] CWE-391 CVE-2023-32871: In DA, there is a possible permission bypass due to an incorrect status check. This could lead to lo In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514.
nvd
CVE-2026-0141P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0141 CVE-2026-0141: In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0137P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0137 CVE-2026-0137: In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privile In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0131P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0131 CVE-2026-0131: In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. Thi In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2026-0133P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0133 CVE-2026-0133: In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootc In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-27824P4HIGHCVSS 7.1v10.0v11.0+1 more2022-04-11
CVE-2022-27824 [HIGH] CWE-125 CVE-2022-27824: Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior t Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file
nvd
Google Android vulnerabilities | cvebase