Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 26 of 339
CVE-2026-0117P3HIGHCVSS 8.4vAndroid kernel2026-03-10
CVE-2026-0117 [HIGH] CWE-787 CVE-2026-0117: In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of bounds write due to an incorrect boun
In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0107P3HIGHCVSS 8.4vAndroid kernel2026-03-10
CVE-2026-0107 [HIGH] CWE-441 CVE-2026-0107: In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a
In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-8860P3HIGHCVSS 8.0v8.0v8.1+2 more2020-02-22
CVE-2020-8860 [HIGH] CWE-121 CVE-2020-8860: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sa
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), P(9.0), Q(10.0) devices with Exynos chipsets. User interaction is required to exploit this vulnerability in that the target must answer a phone call. The specific flaw exists within the Call Control Setup m
nvd
CVE-2024-0040P3HIGHCVSS 7.5v11.0v12.0+8 more2024-02-16
CVE-2024-0040 [HIGH] CWE-787 CVE-2024-0040: In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overfl
In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32929P3HIGHCVSS 8.1vAndroid kernel2024-06-13
CVE-2024-32929 [HIGH] CWE-416 CVE-2024-32929: In gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use after free. This coul
In gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-3821P3CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-08-05
CVE-2016-3821 [CRITICAL] CWE-476 CVE-2016-3821: libmedia in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x
libmedia in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 has certain incorrect declarations, which allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference or memory corruption) via a crafted media file, aka internal bug 28166152.
nvd
CVE-2025-48539P3HIGHCVSS 8.0v15.0v16.0+2 more2025-09-04
CVE-2025-48539 [HIGH] CWE-416 CVE-2025-48539: In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after fre
In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-3741P3CRITICALCVSS 9.8v6.0v6.0.12016-07-11
CVE-2016-3741 [CRITICAL] CWE-20 CVE-2016-3741: The H.264 decoder in mediaserver in Android 6.x before 2016-07-01 does not initialize certain slice
The H.264 decoder in mediaserver in Android 6.x before 2016-07-01 does not initialize certain slice data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28165661.
nvd
CVE-2016-3820P3CRITICALCVSS 9.8v6.0v6.0.12016-08-05
CVE-2016-3820 [CRITICAL] CWE-119 CVE-2016-3820: The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 mishandles slice numbers, which a
The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 mishandles slice numbers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28673410.
nvd
CVE-2025-48645P3HIGHCVSS 7.8v14.0v15.0+5 more2026-03-02
CVE-2025-48645 [HIGH] CWE-269 CVE-2025-48645: In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper i
In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49714P3HIGHCVSS 7.8v13.0v14.0+2 more2025-09-04
CVE-2024-49714 [HIGH] CWE-122 CVE-2024-49714: In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer over
In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22437P3HIGHCVSS 7.8v13.0v132025-09-02
CVE-2025-22437 [HIGH] CWE-693 CVE-2025-22437: In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities
In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0087P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2026-0087 [HIGH] CWE-693 CVE-2026-0087: In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hija
In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0100P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2026-0100 [HIGH] CWE-122 CVE-2026-0100: In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. Th
In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-21050P3CRITICALCVSS 9.8v7.0v7.1.0+4 more2020-04-08
CVE-2018-21050 [CRITICAL] CWE-120 CVE-2018-21050: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.X) (Exynos chipsets) software.
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.X) (Exynos chipsets) software. There is a Buffer overflow in the esecomm Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2018-12852 (October 2018).
nvd
CVE-2019-2006P3CRITICALCVSS 9.8v9.0vAndroid-92019-06-19
CVE-2019-2006 [CRITICAL] CWE-362 CVE-2019-2006: In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after
In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-116665972
nvd
CVE-2025-48592P3HIGHCVSS 7.5v15.0v16.0+2 more2025-12-08
CVE-2025-48592 [HIGH] CWE-125 CVE-2025-48592: In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer ov
In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9426P3HIGHCVSS 7.5v7.0v7.1.1+5 more2024-12-02
CVE-2018-9426 [HIGH] CWE-331 CVE-2018-9426: In RsaKeyPairGenerator::getNumberOfIterations of RSAKeyPairGenerator.java, an incorrect implementat
In RsaKeyPairGenerator::getNumberOfIterations of RSAKeyPairGenerator.java, an incorrect implementation could cause weak RSA key pairs being generated. This could lead to crypto vulnerability with no additional execution privileges needed. User interaction is not needed for exploitation. Bulletin Fix: The fix is designed to correctly implement the key gen
nvd
CVE-2015-3837P3CRITICALCVSS 9.3≤ 5.12015-10-01
CVE-2015-3837 [CRITICAL] CWE-20 CVE-2015-3837: The OpenSSLX509Certificate class in org/conscrypt/OpenSSLX509Certificate.java in Android before 5.1.
The OpenSSLX509Certificate class in org/conscrypt/OpenSSLX509Certificate.java in Android before 5.1.1 LMY48I improperly includes certain context data during serialization and deserialization, which allows attackers to execute arbitrary code via an application that sends a crafted Intent, aka internal bug 21437603.
nvd
CVE-2017-0541P3HIGHCVSS 7.8v4.0v4.0.1+26 more2017-04-07
CVE-2017-0541 [HIGH] CWE-119 CVE-2017-0541: A remote code execution vulnerability in sonivox in Mediaserver could enable an attacker using a spe
A remote code execution vulnerability in sonivox in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 4.4.4, 5.0.2,
nvd