Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 250 of 339
CVE-2025-32317P4MEDIUMCVSS 5.5v16.0v162025-09-05
CVE-2025-32317 [MEDIUM] CWE-441 CVE-2025-32317: In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead
In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48648P4MEDIUMCVSS 5.5v14.0v15.0+4 more2026-06-01
CVE-2025-48648 [MEDIUM] CWE-400 CVE-2025-48648: In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource
In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-28578P4MEDIUMCVSS 5.5v14.0v15.0+8 more2026-06-01
CVE-2026-28578 [MEDIUM] CWE-20 CVE-2026-28578: In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistenc
In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-20580P4MEDIUMCVSS 5.3v9.02020-03-24
CVE-2019-20580 [MEDIUM] CVE-2019-20580: An issue was discovered on Samsung mobile devices with P(9.0) software. The Motion photo player allo
An issue was discovered on Samsung mobile devices with P(9.0) software. The Motion photo player allows attackers to bypass the Secure Folder feature to view images. The Samsung ID is SVE-2019-14653 (August 2019).
nvd
CVE-2019-20539P4MEDIUMCVSS 5.3v7.0v7.1.0+5 more2020-03-24
CVE-2019-20539 [MEDIUM] CWE-125 CVE-2019-20539: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Broadcom chipsets
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Broadcom chipsets) software. An out-of-bounds Read in the Wi-Fi vendor command leads to an information leak. The Samsung ID is SVE-2019-14869 (November 2019).
nvd
CVE-2020-35552P4MEDIUMCVSS 5.3v8.0v8.1+2 more2020-12-18
CVE-2020-35552 [MEDIUM] CVE-2020-35552: An issue was discovered in the GPS daemon on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0)
An issue was discovered in the GPS daemon on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (non-Qualcomm chipsets) software. Attackers can obtain sensitive location information because the configuration file is incorrect. The Samsung ID is SVE-2020-18678 (December 2020).
nvd
CVE-2020-26599P4MEDIUMCVSS 5.3v10.02020-10-06
CVE-2020-26599 [MEDIUM] CWE-306 CVE-2020-26599: An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms
An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can be accepted without authentication. The Samsung ID is SVE-2020-17079 (October 2020).
nvd
CVE-2016-11032P4MEDIUMCVSS 5.3v6.02020-04-07
CVE-2016-11032 [MEDIUM] CWE-20 CVE-2016-11032: An issue was discovered on Samsung mobile devices with M(6.0) software. An attacker can disable all
An issue was discovered on Samsung mobile devices with M(6.0) software. An attacker can disable all Sound functionality by broadcasting an unprotected intent. The Samsung IDs are SVE-2016-7179 and SVE-2016-7182 (November 2016).
nvd
CVE-2017-0860P4MEDIUMCVSS 5.3v5.0.2v5.1.1+5 more2017-11-16
CVE-2017-0860 [MEDIUM] CVE-2017-0860: An elevation of privilege vulnerability in the Android system (inputdispatcher). Product: Android. V
An elevation of privilege vulnerability in the Android system (inputdispatcher). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-31097064.
nvd
CVE-2022-39847P4MEDIUMCVSS 5.3v10.0v11.0+1 more2022-10-07
CVE-2022-39847 [MEDIUM] CWE-416 CVE-2022-39847: Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR O
Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 allows attackers to perform malicious actions.
nvd
CVE-2015-6631P4MEDIUMCVSS 5.0≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-6631 [MEDIUM] CWE-200 CVE-2015-6631: libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to o
libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24623447.
nvd
CVE-2025-0087P4MEDIUMCVSS 5.1v13.0v14.0+4 more2025-09-04
CVE-2025-0087 [MEDIUM] CWE-689 CVE-2025-0087: In onCreate of UninstallerActivity.java, there is a possible way to uninstall a different user's app
In onCreate of UninstallerActivity.java, there is a possible way to uninstall a different user's app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0348P4MEDIUMCVSS 4.9v11.0vAndroid-112020-09-18
CVE-2020-0348 [MEDIUM] CWE-125 CVE-2020-0348: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to rem
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over NFC with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139188582
nvd
CVE-2020-0157P4MEDIUMCVSS 4.9v10.0vAndroid-102020-06-11
CVE-2020-0157 [MEDIUM] CWE-125 CVE-2020-0157: In nfa_hci_conn_cback of nfa_hci_main.cc, there is a possible out of bounds read due to a missing bo
In nfa_hci_conn_cback of nfa_hci_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure via compromised device firmware with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139740814
nvd
CVE-2015-9546P4MEDIUMCVSS 4.8v4.42020-04-10
CVE-2015-9546 [MEDIUM] CWE-22 CVE-2015-9546: An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences into an extracted file path. The Samsung ID is SVE-2015-4363 (November 2015
nvd
CVE-2017-0778P4HIGHCVSS 7.1v5.0v5.0.1+10 more2017-09-08
CVE-2017-0778 [HIGH] CWE-200 CVE-2017-0778: A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versi
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-62133227.
nvd
CVE-2026-0130P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0130 CVE-2026-0130: In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow.
In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2026-0165P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0165 CVE-2026-0165: In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a mis
In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2026-0155P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0155 CVE-2026-0155: In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. Th
In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0157P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0157 CVE-2026-0157: In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This co
In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd