cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 237 of 339
CVE-2023-40641P4MEDIUMCVSS 5.5v11.0v12.02023-10-08
CVE-2023-40641 [MEDIUM] CWE-862 CVE-2023-40641: In Messaging, there is a possible missing permission check. This could lead to local information dis In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40633P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-10-08
CVE-2023-40633 [MEDIUM] CWE-862 CVE-2023-40633: In phasecheckserver, there is a possible missing permission check. This could lead to local informat In phasecheckserver, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40646P4MEDIUMCVSS 5.5v11.0v12.02023-10-08
CVE-2023-40646 [MEDIUM] CWE-862 CVE-2023-40646: In Messaging, there is a possible missing permission check. This could lead to local information dis In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40643P4MEDIUMCVSS 5.5v11.0v12.02023-10-08
CVE-2023-40643 [MEDIUM] CWE-862 CVE-2023-40643: In Messaging, there is a possible missing permission check. This could lead to local information dis In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40648P4MEDIUMCVSS 5.5v11.0v12.02023-10-08
CVE-2023-40648 [MEDIUM] CWE-862 CVE-2023-40648: In Messaging, there is a possible missing permission check. This could lead to local information dis In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40649P4MEDIUMCVSS 5.5v11.0v12.02023-10-08
CVE-2023-40649 [MEDIUM] CWE-862 CVE-2023-40649: In Messaging, there is a possible missing permission check. This could lead to local information dis In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40645P4MEDIUMCVSS 5.5v11.0v12.02023-10-08
CVE-2023-40645 [MEDIUM] CWE-862 CVE-2023-40645: In Messaging, there is a possible missing permission check. This could lead to local information dis In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40639P4MEDIUMCVSS 5.5v10.02023-10-08
CVE-2023-40639 [MEDIUM] CWE-862 CVE-2023-40639: In SoundRecorder service, there is a possible missing permission check. This could lead to local inf In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2023-38465P4MEDIUMCVSS 5.5v11.0v12.02023-09-04
CVE-2023-38465 [MEDIUM] CWE-862 CVE-2023-38465: In ims service, there is a possible missing permission check. This could lead to local information d In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2023-38440P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38440 [MEDIUM] CWE-862 CVE-2023-38440: In vowifiservice, there is a possible missing permission check.This could lead to local information In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2023-38454P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38454 [MEDIUM] CWE-862 CVE-2023-38454: In vowifi service, there is a possible missing permission check.This could lead to local information In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2023-38441P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38441 [MEDIUM] CWE-862 CVE-2023-38441: In vowifiservice, there is a possible missing permission check.This could lead to local information In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2023-38466P4MEDIUMCVSS 5.5v11.0v12.02023-09-04
CVE-2023-38466 [MEDIUM] CWE-862 CVE-2023-38466: In ims service, there is a possible missing permission check. This could lead to local information d In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2023-38442P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38442 [MEDIUM] CWE-862 CVE-2023-38442: In vowifiservice, there is a possible missing permission check.This could lead to local information In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2018-9421P4MEDIUMCVSS 5.5v6.0v6.0.1+10 more2024-11-19
CVE-2018-9421 [MEDIUM] CWE-908 CVE-2018-9421: In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder, In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder, due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32910P4MEDIUMCVSS 5.5vAndroid kernel2024-06-13
CVE-2024-32910 [MEDIUM] CWE-908 CVE-2024-32910: In handle_msg_shm_map_req of trusty/user/base/lib/spi/srv/tipc/tipc.c, there is a possible stack dat In handle_msg_shm_map_req of trusty/user/base/lib/spi/srv/tipc/tipc.c, there is a possible stack data disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0043P4MEDIUMCVSS 5.5v14.0v15.0+8 more2026-06-01
CVE-2026-0043 [MEDIUM] CWE-190 CVE-2026-0043: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of servic In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26437P4MEDIUMCVSS 5.5v15.0v152025-09-04
CVE-2025-26437 [MEDIUM] CWE-862 CVE-2025-26437: In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retriev In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0079P4MEDIUMCVSS 5.5v14.0v15.0+8 more2026-06-01
CVE-2026-0079 [MEDIUM] CWE-190 CVE-2026-0079: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of servic In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48560P4MEDIUMCVSS 5.5v14.0v142025-09-04
CVE-2025-48560 [MEDIUM] CWE-441 CVE-2025-48560: In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confuse In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase