Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 246 of 339
CVE-2023-21344P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21344 [MEDIUM] CWE-203 CVE-2023-21344: In Job Scheduler, there is a possible way to determine whether an app is installed, without query pe
In Job Scheduler, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21205P4MEDIUMCVSS 5.5v13.0vAndroid-132023-06-28
CVE-2023-21205 [MEDIUM] CWE-502 CVE-2023-21205: In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe
In startWpsPinDisplayInternal of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262245376
nvd
CVE-2023-21105P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-06-15
CVE-2023-21105 [MEDIUM] CWE-918 CVE-2023-21105: In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a co
In multiple functions of ChooserActivity.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-26103656
nvd
CVE-2021-25382P4MEDIUMCVSS 5.5v8.0v8.1+3 more2021-04-23
CVE-2021-25382 [MEDIUM] CWE-285 CVE-2021-25382: An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release
An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secure Folder via debugging command.
nvd
CVE-2023-21331P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21331 [MEDIUM] CWE-203 CVE-2023-21331: In InputMethod, there is a possible way to determine whether an app is installed, without query perm
In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21335P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21335 [MEDIUM] CWE-203 CVE-2023-21335: In Settings, there is a possible way to determine whether an app is installed, without query permiss
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21336P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21336 [MEDIUM] CWE-203 CVE-2023-21336: In Input Method, there is a possible way to determine whether an app is installed, without query per
In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-39753P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39753 [MEDIUM] CWE-862 CVE-2021-39753: In DomainVerificationService, there is a possible way to access app domain verification information
In DomainVerificationService, there is a possible way to access app domain verification information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-200035185
nvd
CVE-2021-39747P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39747 [MEDIUM] CWE-276 CVE-2021-39747: In Settings Provider, there is a possible way to list values of non-readable global settings due to
In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-208268457
nvd
CVE-2021-39748P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39748 [MEDIUM] CWE-276 CVE-2021-39748: In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an
In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-203777141
nvd
CVE-2025-27701P4MEDIUMCVSS 5.5vAndroid kernel2025-05-27
CVE-2025-27701 [MEDIUM] CWE-476 CVE-2025-27701: In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is
In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Later this values will be derefenced without prior NULL check, which can lead to local Temporary DoS or OOB Read, leading to information disclosure.
nvd
CVE-2023-48399P4MEDIUMCVSS 5.5vAndroid kernel2023-12-08
CVE-2023-48399 [MEDIUM] CWE-125 CVE-2023-48399: In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bound
In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2023-48408P4MEDIUMCVSS 5.5vAndroid kernel2023-12-08
CVE-2023-48408 [MEDIUM] CWE-125 CVE-2023-48408: In ProtocolNetSimFileInfoAdapter() of protocolnetadapter.cpp, there is a possible out of bounds read
In ProtocolNetSimFileInfoAdapter() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2023-48411P4MEDIUMCVSS 5.5vAndroid kernel2023-12-08
CVE-2023-48411 [MEDIUM] CWE-125 CVE-2023-48411: In SignalStrengthAdapter::FillGsmSignalStrength() of protocolmiscadapter.cpp, there is a possible ou
In SignalStrengthAdapter::FillGsmSignalStrength() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2023-21330P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21330 [MEDIUM] CWE-203 CVE-2023-21330: In Overlay Manager, there is a possible way to determine whether an app is installed, without query
In Overlay Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-21764P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-07-06
CVE-2022-21764 [MEDIUM] CWE-862 CVE-2022-21764: In telecom service, there is a possible information disclosure due to a missing permission check. Th
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID: ALPS07044717.
nvd
CVE-2022-21763P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-07-06
CVE-2022-21763 [MEDIUM] CWE-862 CVE-2022-21763: In telecom service, there is a possible information disclosure due to a missing permission check. Th
In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044717; Issue ID: ALPS07044708.
nvd
CVE-2022-20115P4MEDIUMCVSS 5.5v12.0v12.1+1 more2022-05-10
CVE-2022-20115 [MEDIUM] CWE-862 CVE-2022-20115: In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base sta
In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information without location permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12
nvd
CVE-2022-20225P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-07-13
CVE-2022-20225 [MEDIUM] CWE-862 CVE-2022-20225: In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive i
In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 And
nvd
CVE-2022-21749P4MEDIUMCVSS 5.5v11.0v12.02022-06-06
CVE-2022-21749 [MEDIUM] CWE-862 CVE-2022-21749: In telephony, there is a possible information disclosure due to a missing permission check. This cou
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06511058; Issue ID: ALPS06511058.
nvd