cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 260 of 339
CVE-2022-20467P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-03-24
CVE-2022-20467 [MEDIUM] CVE-2022-20467: In isBluetoothShareUri of BluetoothOppUtility.java, there is a possible incorrect file read due to a In isBluetoothShareUri of BluetoothOppUtility.java, there is a possible incorrect file read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-225880741
nvd
CVE-2021-39751P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39751 [MEDIUM] CWE-862 CVE-2021-39751: In Settings, there is a possible way to read Bluetooth device names without proper permissions due t In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-172838801
nvd
CVE-2021-39769P4MEDIUMCVSS 5.5v12.1vAndroid-12L2022-03-30
CVE-2021-39769 [MEDIUM] CWE-276 CVE-2021-39769: In Device Policy, there is a possible way to determine whether an app is installed, without query pe In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-193663287
nvd
CVE-2021-39779P4MEDIUMCVSS 5.5v12.0vAndroid-12L2022-03-30
CVE-2021-39779 [MEDIUM] CWE-276 CVE-2021-39779: In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call state with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-190400974
nvd
CVE-2021-39774P4MEDIUMCVSS 5.5v12.0vAndroid-12L2022-03-30
CVE-2021-39774 [MEDIUM] CWE-125 CVE-2021-39774: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-205989472
nvd
CVE-2022-30758P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-07-12
CVE-2022-30758 [MEDIUM] CWE-276 CVE-2022-30758: Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attac Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with privilege of Finder.
nvd
CVE-2024-49740P4MEDIUMCVSS 5.5v12.0v12.1+8 more2025-08-26
CVE-2024-49740 [MEDIUM] CWE-400 CVE-2024-49740: In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43083P4MEDIUMCVSS 5.5v12.0v12.1+8 more2024-11-13
CVE-2024-43083 [MEDIUM] CWE-770 CVE-2024-43083: In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21296P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21296 [MEDIUM] CWE-203 CVE-2023-21296: In Permission, there is a possible way to determine whether an app is installed, without query permi In Permission, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-20278P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20278 [MEDIUM] CWE-532 CVE-2022-20278: In Accounts, there is a possible way to write sensitive information to the system log due to insuffi In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-205130113
nvd
CVE-2022-20270P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20270 [MEDIUM] CVE-2022-20270: In Content, there is a possible way to learn gmail account name on the device due to a permissions b In Content, there is a possible way to learn gmail account name on the device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-209005023
nvd
CVE-2022-20357P4MEDIUMCVSS 5.5v12.0v12.1+1 more2022-08-10
CVE-2022-20357 [MEDIUM] CWE-908 CVE-2022-20357: In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitiali In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-214999987
nvd
CVE-2023-21383P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21383 [MEDIUM] CVE-2023-21383: In Settings, there is a possible way for the user to unintentionally send extra data due to an uncle In Settings, there is a possible way for the user to unintentionally send extra data due to an unclear prompt. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-44421P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-44421 [MEDIUM] CWE-862 CVE-2022-44421: In wlan driver, there is a possible missing permission check. This could lead to local In wlan drive In wlan driver, there is a possible missing permission check. This could lead to local In wlan driver, information disclosure.
nvd
CVE-2023-35677P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-09-11
CVE-2023-35677 [MEDIUM] CWE-862 CVE-2023-35677: In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20323P4MEDIUMCVSS 5.5v13.0vAndroid-132022-08-12
CVE-2022-20323 [MEDIUM] CWE-862 CVE-2022-20323: In PackageManager, there is a possible package installation disclosure due to a missing permission c In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-187176203
nvd
CVE-2025-26456P4MEDIUMCVSS 5.5v14.0v15.0+2 more2025-09-04
CVE-2025-26456 [MEDIUM] CWE-703 CVE-2025-26456: In multiple functions of DexUseManagerLocal.java, there is a possible way to crash system server due In multiple functions of DexUseManagerLocal.java, there is a possible way to crash system server due to a logic error in the code. This could lead to local permanent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20665P4MEDIUMCVSS 5.5v13.0v14.0+1 more2025-05-05
CVE-2025-20665 [MEDIUM] CWE-538 CVE-2025-20665: In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could l In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local information disclosure of device identifier with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09555228; Issue ID: MSV-2760.
nvd
CVE-2023-21302P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21302 [MEDIUM] CWE-203 CVE-2023-21302: In Package Manager, there is a possible way to determine whether an app is installed, without query In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21306P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21306 [MEDIUM] CWE-203 CVE-2023-21306: In ContentService, there is a possible way to read installed sync content providers due to side chan In ContentService, there is a possible way to read installed sync content providers due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase