Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 248 of 339
CVE-2023-20972P4MEDIUMCVSS 5.5v13.0vAndroid-132023-03-24
CVE-2023-20972 [MEDIUM] CWE-119 CVE-2023-20972: In btm_vendor_specific_evt of btm_devctl.cc, there is a possible out of bounds read due to a missing
In btm_vendor_specific_evt of btm_devctl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-255304665
nvd
CVE-2022-20341P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20341 [MEDIUM] CWE-862 CVE-2022-20341: In ConnectivityService, there is a possible bypass of network permissions due to a missing permissio
In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could lead to local information disclosure of tethering interfaces with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-162952629
nvd
CVE-2022-28780P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-05-03
CVE-2022-28780 [MEDIUM] CWE-284 CVE-2022-28780: Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attacke
Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.
nvd
CVE-2025-48590P4MEDIUMCVSS 5.5v13.0v14.0+6 more2025-12-08
CVE-2025-48590 [MEDIUM] CWE-400 CVE-2025-48590: In verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to preve
In verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21276P4MEDIUMCVSS 5.5v12.0v12.1+4 more2023-08-14
CVE-2023-21276 [MEDIUM] CWE-908 CVE-2023-21276: In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialize
In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21239P4MEDIUMCVSS 5.5v12.0v12.1+4 more2023-07-13
CVE-2023-21239 [MEDIUM] CWE-384 CVE-2023-21239: In visitUris of Notification.java, there is a possible way to leak image data across user boundaries
In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20259P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20259 [MEDIUM] CWE-862 CVE-2022-20259: In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This coul
In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-221431393
nvd
CVE-2022-20312P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20312 [MEDIUM] CWE-862 CVE-2022-20312: In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to mis
In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission check. This could lead to local information disclosure without additional execution privileges needed. User interaction is not needed forexploitationProduct: AndroidVersions: Android-13Android ID: A-192244925
nvd
CVE-2022-20352P4MEDIUMCVSS 5.5v12.0v12.1+1 more2022-08-10
CVE-2022-20352 [MEDIUM] CWE-862 CVE-2022-20352: In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which
In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android
nvd
CVE-2023-21326P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21326 [MEDIUM] CWE-203 CVE-2023-21326: In Package Manager Service, there is a possible way to determine whether an app is installed, withou
In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9407P4MEDIUMCVSS 5.5vKernel2024-12-05
CVE-2018-9407 [MEDIUM] CWE-125 CVE-2018-9407: In emmc_rpmb_ioctl of emmc_rpmb.c, there is an Information Disclosure due to a Missing Bounds Check.
In emmc_rpmb_ioctl of emmc_rpmb.c, there is an Information Disclosure due to a Missing Bounds Check. This could lead to Information Disclosure of kernel data.
nvd
CVE-2023-20935P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-04-19
CVE-2023-20935 [MEDIUM] CWE-125 CVE-2023-20935: In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds che
In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-256589724
nvd
CVE-2023-21367P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21367 [MEDIUM] CVE-2023-21367: In Scudo, there is a possible way to exploit certain heap OOB read/write issues due to an insecure i
In Scudo, there is a possible way to exploit certain heap OOB read/write issues due to an insecure implementation/design. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21301P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21301 [MEDIUM] CWE-203 CVE-2023-21301: In ActivityManagerService, there is a possible way to determine whether an app is installed, without
In ActivityManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21354P4MEDIUMCVSS 5.5v14.0v142023-10-30
CVE-2023-21354 [MEDIUM] CWE-203 CVE-2023-21354: In Package Manager Service, there is a possible way to determine whether an app is installed, withou
In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21143P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-06-15
CVE-2023-21143 [MEDIUM] CWE-20 CVE-2023-21143: In multiple functions of multiple files, there is a possible way to make the device unusable due to
In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-268
nvd
CVE-2018-9345P4MEDIUMCVSS 5.5v6.0v6.0.1+10 more2024-11-19
CVE-2018-9345 [MEDIUM] CWE-908 CVE-2018-9345: In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information discl
In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9346P4MEDIUMCVSS 5.5v6.0v6.0.1+10 more2024-11-19
CVE-2018-9346 [MEDIUM] CWE-908 CVE-2018-9346: In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information discl
In BnAudioPolicyService::onTransact of AudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21142P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-06-15
CVE-2023-21142 [MEDIUM] CWE-732 CVE-2023-21142: In multiple files, there is a possible way to access traces in the dev mode due to a permissions byp
In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-262243665
nvd
CVE-2024-29785P4MEDIUMCVSS 5.5vAndroid kernel2024-06-13
CVE-2024-29785 [MEDIUM] CWE-908 CVE-2024-29785: In aur_get_state of aurora.c, there is a possible information disclosure due to uninitialized data.
In aur_get_state of aurora.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd