Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 237 of 339
CVE-2023-40641P4MEDIUMCVSS 5.5v11.0v12.02023-10-08
CVE-2023-40641 [MEDIUM] CWE-862 CVE-2023-40641: In Messaging, there is a possible missing permission check. This could lead to local information dis
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40633P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-10-08
CVE-2023-40633 [MEDIUM] CWE-862 CVE-2023-40633: In phasecheckserver, there is a possible missing permission check. This could lead to local informat
In phasecheckserver, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40646P4MEDIUMCVSS 5.5v11.0v12.02023-10-08
CVE-2023-40646 [MEDIUM] CWE-862 CVE-2023-40646: In Messaging, there is a possible missing permission check. This could lead to local information dis
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40643P4MEDIUMCVSS 5.5v11.0v12.02023-10-08
CVE-2023-40643 [MEDIUM] CWE-862 CVE-2023-40643: In Messaging, there is a possible missing permission check. This could lead to local information dis
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40648P4MEDIUMCVSS 5.5v11.0v12.02023-10-08
CVE-2023-40648 [MEDIUM] CWE-862 CVE-2023-40648: In Messaging, there is a possible missing permission check. This could lead to local information dis
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40649P4MEDIUMCVSS 5.5v11.0v12.02023-10-08
CVE-2023-40649 [MEDIUM] CWE-862 CVE-2023-40649: In Messaging, there is a possible missing permission check. This could lead to local information dis
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40645P4MEDIUMCVSS 5.5v11.0v12.02023-10-08
CVE-2023-40645 [MEDIUM] CWE-862 CVE-2023-40645: In Messaging, there is a possible missing permission check. This could lead to local information dis
In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
nvd
CVE-2023-40639P4MEDIUMCVSS 5.5v10.02023-10-08
CVE-2023-40639 [MEDIUM] CWE-862 CVE-2023-40639: In SoundRecorder service, there is a possible missing permission check. This could lead to local inf
In SoundRecorder service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2023-38465P4MEDIUMCVSS 5.5v11.0v12.02023-09-04
CVE-2023-38465 [MEDIUM] CWE-862 CVE-2023-38465: In ims service, there is a possible missing permission check. This could lead to local information d
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2023-38440P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38440 [MEDIUM] CWE-862 CVE-2023-38440: In vowifiservice, there is a possible missing permission check.This could lead to local information
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2023-38454P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38454 [MEDIUM] CWE-862 CVE-2023-38454: In vowifi service, there is a possible missing permission check.This could lead to local information
In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2023-38441P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38441 [MEDIUM] CWE-862 CVE-2023-38441: In vowifiservice, there is a possible missing permission check.This could lead to local information
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2023-38466P4MEDIUMCVSS 5.5v11.0v12.02023-09-04
CVE-2023-38466 [MEDIUM] CWE-862 CVE-2023-38466: In ims service, there is a possible missing permission check. This could lead to local information d
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2023-38442P4MEDIUMCVSS 5.5v11.02023-09-04
CVE-2023-38442 [MEDIUM] CWE-862 CVE-2023-38442: In vowifiservice, there is a possible missing permission check.This could lead to local information
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
nvd
CVE-2018-9421P4MEDIUMCVSS 5.5v6.0v6.0.1+10 more2024-11-19
CVE-2018-9421 [MEDIUM] CWE-908 CVE-2018-9421: In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder,
In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder, due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32910P4MEDIUMCVSS 5.5vAndroid kernel2024-06-13
CVE-2024-32910 [MEDIUM] CWE-908 CVE-2024-32910: In handle_msg_shm_map_req of trusty/user/base/lib/spi/srv/tipc/tipc.c, there is a possible stack dat
In handle_msg_shm_map_req of trusty/user/base/lib/spi/srv/tipc/tipc.c, there is a possible stack data disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0043P4MEDIUMCVSS 5.5v14.0v15.0+8 more2026-06-01
CVE-2026-0043 [MEDIUM] CWE-190 CVE-2026-0043: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of servic
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26437P4MEDIUMCVSS 5.5v15.0v152025-09-04
CVE-2025-26437 [MEDIUM] CWE-862 CVE-2025-26437: In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retriev
In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0079P4MEDIUMCVSS 5.5v14.0v15.0+8 more2026-06-01
CVE-2026-0079 [MEDIUM] CWE-190 CVE-2026-0079: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of servic
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48560P4MEDIUMCVSS 5.5v14.0v142025-09-04
CVE-2025-48560 [MEDIUM] CWE-441 CVE-2025-48560: In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confuse
In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd