Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 263 of 339
CVE-2025-48559P4MEDIUMCVSS 5.5v13.0v14.0+6 more2025-09-04
CVE-2025-48559 [MEDIUM] CWE-20 CVE-2025-48559: In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due t
In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23712P4MEDIUMCVSS 5.5v12.0v12.1+6 more2024-05-07
CVE-2024-23712 [MEDIUM] CWE-400 CVE-2024-23712: In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /dat
In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-47329P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47329 [MEDIUM] CWE-862 CVE-2022-47329: In wlan driver, there is a possible missing permission check. This could lead to local information d
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
nvd
CVE-2022-47328P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47328 [MEDIUM] CWE-862 CVE-2022-47328: In wlan driver, there is a possible missing permission check. This could lead to local information d
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
nvd
CVE-2022-47325P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47325 [MEDIUM] CWE-862 CVE-2022-47325: In wlan driver, there is a possible missing permission check. This could lead to local information d
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
nvd
CVE-2022-47324P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47324 [MEDIUM] CWE-862 CVE-2022-47324: In wlan driver, there is a possible missing permission check. This could lead to local information d
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
nvd
CVE-2022-47326P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47326 [MEDIUM] CWE-862 CVE-2022-47326: In wlan driver, there is a possible missing permission check. This could lead to local information d
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
nvd
CVE-2023-21350P4MEDIUMCVSS 5.5v14.0v142023-10-30
CVE-2023-21350 [MEDIUM] CWE-203 CVE-2023-21350: In Media Projection, there is a possible way to determine whether an app is installed, without query
In Media Projection, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21091P4MEDIUMCVSS 5.5v13.0vAndroid-132023-04-19
CVE-2023-21091 [MEDIUM] CWE-862 CVE-2023-21091: In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app l
In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:
nvd
CVE-2024-40659P4MEDIUMCVSS 5.5v14.0v142024-09-11
CVE-2024-40659 [MEDIUM] CWE-120 CVE-2024-40659: In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable
In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not nee
nvd
CVE-2024-40656P4MEDIUMCVSS 5.5v12.0v12.1+6 more2024-09-11
CVE-2024-40656 [MEDIUM] CWE-125 CVE-2024-40656: In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to revea
In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-21104P4MEDIUMCVSS 5.5v12.1v13.0+1 more2023-05-15
CVE-2023-21104 [MEDIUM] CWE-276 CVE-2023-21104: In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local info
In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-259938771
nvd
CVE-2023-21082P4MEDIUMCVSS 5.5v11.0v12.0+3 more2023-04-19
CVE-2023-21082 [MEDIUM] CWE-441 CVE-2023-21082: In getNumberFromCallIntent of NewOutgoingCallIntentBroadcaster.java, there is a possible way to enum
In getNumberFromCallIntent of NewOutgoingCallIntentBroadcaster.java, there is a possible way to enumerate other user's contact phone number due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 An
nvd
CVE-2022-42782P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-06
CVE-2022-42782 [MEDIUM] CWE-200 CVE-2022-42782: In wlan driver, there is a possible missing permission check, This could lead to local information d
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
nvd
CVE-2023-48351P4MEDIUMCVSS 5.5v11.0v12.02024-01-18
CVE-2023-48351 [MEDIUM] CWE-787 CVE-2023-48351: In video decoder, there is a possible out of bounds write due to a missing bounds check. This could
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-48350P4MEDIUMCVSS 5.5v11.0v12.02024-01-18
CVE-2023-48350 [MEDIUM] CWE-787 CVE-2023-48350: In video decoder, there is a possible out of bounds write due to a missing bounds check. This could
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-48349P4MEDIUMCVSS 5.5v11.0v12.02024-01-18
CVE-2023-48349 [MEDIUM] CWE-787 CVE-2023-48349: In video decoder, there is a possible out of bounds write due to a missing bounds check. This could
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-48340P4MEDIUMCVSS 5.5v11.0v12.02024-01-18
CVE-2023-48340 [MEDIUM] CWE-787 CVE-2023-48340: In video decoder, there is a possible out of bounds write due to improper input validation. This cou
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-48343P4MEDIUMCVSS 5.5v11.0v12.02024-01-18
CVE-2023-48343 [MEDIUM] CWE-787 CVE-2023-48343: In video decoder, there is a possible out of bounds write due to improper input validation. This cou
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-48352P4MEDIUMCVSS 5.5v11.0v12.0+1 more2024-01-18
CVE-2023-48352 [MEDIUM] CWE-787 CVE-2023-48352: In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This cou
In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
nvd