Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 249 of 339
CVE-2025-26463P4MEDIUMCVSS 5.5v13.0v14.0+4 more2025-09-04
CVE-2025-26463 [MEDIUM] CWE-400 CVE-2025-26463: In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allo
In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This could lead to a local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34663P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-10-08
CVE-2024-34663 [MEDIUM] CWE-190 CVE-2024-34663: Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write
Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory.
nvd
CVE-2025-48576P4MEDIUMCVSS 5.5v13.0v14.0+6 more2025-12-08
CVE-2025-48576 [MEDIUM] CWE-400 CVE-2025-48576: In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is
In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22431P4MEDIUMCVSS 5.5v13.0v14.0+4 more2025-09-02
CVE-2025-22431 [MEDIUM] CWE-693 CVE-2025-22431: In multiple locations, there is a possible method for a malicious app to prevent dialing emergency s
In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logic error in the code. This could lead to local denial of service until the phone reboots with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34742P4MEDIUMCVSS 5.5v14.0v142024-08-15
CVE-2024-34742 [MEDIUM] CWE-843 CVE-2024-34742: In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from bei
In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47019P4MEDIUMCVSS 5.5vAndroid kernel2024-10-25
CVE-2024-47019 [MEDIUM] CWE-125 CVE-2024-47019: In ProtocolEmbmsSaiListAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bound
In ProtocolEmbmsSaiListAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.
nvd
CVE-2025-21024P4MEDIUMCVSS 5.5fixed in 16.02025-08-06
CVE-2025-21024 [MEDIUM] CVE-2025-21024: Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local at
Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access sensitive information.
nvd
CVE-2025-20648P4MEDIUMCVSS 5.5v13.0v14.0+1 more2025-03-03
CVE-2025-20648 [MEDIUM] CWE-125 CVE-2025-20648: In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to loc
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09456673; Issue ID: MSV-2584.
nvd
CVE-2024-53839P4MEDIUMCVSS 5.5vAndroid kernel2025-01-03
CVE-2024-53839 [MEDIUM] CWE-125 CVE-2024-53839: In GetCellInfoList() of protocolnetadapter.cpp, there is a possible out of bounds read due to a miss
In GetCellInfoList() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.
nvd
CVE-2018-9420P4MEDIUMCVSS 5.5v6.0v6.0.1+10 more2024-11-19
CVE-2018-9420 [MEDIUM] CWE-908 CVE-2018-9420: In BnCameraService::onTransact of CameraService.cpp, there is a possible information disclosure due
In BnCameraService::onTransact of CameraService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2017-13309P4MEDIUMCVSS 5.5v8.12024-11-15
CVE-2017-13309 [MEDIUM] CVE-2017-13309: In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly u
In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47015P4MEDIUMCVSS 5.5vAndroid kernel2024-10-25
CVE-2024-47015 [MEDIUM] CWE-125 CVE-2024-47015: In ProtocolMiscHwConfigChangeAdapter::GetData() of protocolmiscadapter.cpp, there is a possible out-
In ProtocolMiscHwConfigChangeAdapter::GetData() of protocolmiscadapter.cpp, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User Interaction is not needed for exploitation.
nvd
CVE-2024-32914P4MEDIUMCVSS 5.5vAndroid kernel2024-06-13
CVE-2024-32914 [MEDIUM] CWE-125 CVE-2024-32914: In tpu_get_int_state of tpu.c, there is a possible information disclosure due to uninitialized data.
In tpu_get_int_state of tpu.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48607P4MEDIUMCVSS 5.5v15.0v16.0+2 more2025-12-08
CVE-2025-48607 [MEDIUM] CVE-2025-48607: In multiple locations, there is a possible way to create a large amount of app ops due to a logic er
In multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20219P4MEDIUMCVSS 5.5v10.0v11.0+3 more2022-07-13
CVE-2022-20219 [MEDIUM] CWE-312 CVE-2022-20219: In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible
In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: An
nvd
CVE-2025-48601P4MEDIUMCVSS 5.5v13.0v14.0+6 more2025-12-08
CVE-2025-48601 [MEDIUM] CWE-20 CVE-2025-48601: In multiple locations, there is a possible permanent denial of service due to improper input validat
In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49736P4MEDIUMCVSS 5.5v12.0v12.1+6 more2025-01-21
CVE-2024-49736 [MEDIUM] CWE-783 CVE-2024-49736: In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user
In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0070P4MEDIUMCVSS 5.5v14.0v15.0+8 more2026-06-01
CVE-2026-0070 [MEDIUM] CWE-20 CVE-2026-0070: In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system c
In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0060P4MEDIUMCVSS 5.5v14.0v15.0+8 more2026-06-01
CVE-2026-0060 [MEDIUM] CVE-2026-0060: In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persis
In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0085P4MEDIUMCVSS 5.5v14.0v15.0+8 more2026-06-01
CVE-2026-0085 [MEDIUM] CWE-20 CVE-2026-0085: In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact
In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd