Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 264 of 339
CVE-2023-48348P4MEDIUMCVSS 5.5v11.0v12.02024-01-18
CVE-2023-48348 [MEDIUM] CWE-787 CVE-2023-48348: In video decoder, there is a possible out of bounds write due to improper input validation. This cou
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
nvd
CVE-2023-21362P4MEDIUMCVSS 5.5fixed in 14.0v142023-10-30
CVE-2023-21362 [MEDIUM] CVE-2023-21362: In Usage, there is a possible permanent DoS due to resource exhaustion. This could lead to local den
In Usage, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-42766P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-12-06
CVE-2022-42766 [MEDIUM] CWE-200 CVE-2022-42766: In wlan driver, there is a possible missing permission check, This could lead to local information d
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
nvd
CVE-2025-48603P4MEDIUMCVSS 5.5v13.0v14.0+6 more2025-12-08
CVE-2025-48603 [MEDIUM] CWE-770 CVE-2025-48603: In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to r
In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20980P4MEDIUMCVSS 5.5fixed in 15.02025-05-07
CVE-2025-20980 [MEDIUM] CWE-787 CVE-2025-20980: Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corrupt
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.
nvd
CVE-2023-20824P4MEDIUMCVSS 5.5v12.0v13.02023-09-04
CVE-2023-20824 [MEDIUM] CWE-862 CVE-2023-20824: In duraspeed, there is a possible information disclosure due to a missing permission check. This cou
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID: ALPS07951402.
nvd
CVE-2023-20825P4MEDIUMCVSS 5.5v12.0v13.02023-09-04
CVE-2023-20825 [MEDIUM] CWE-862 CVE-2023-20825: In duraspeed, there is a possible information disclosure due to a missing permission check. This cou
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID: ALPS07951413.
nvd
CVE-2025-26429P4MEDIUMCVSS 5.5v13.0v14.0+4 more2025-09-04
CVE-2025-26429 [MEDIUM] CWE-20 CVE-2025-26429: In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper
In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26432P4MEDIUMCVSS 5.5v15.0v152025-09-04
CVE-2025-26432 [MEDIUM] CWE-130 CVE-2025-26432: In multiple locations, there is a possible way to persistently DoS the device due to a missing lengt
In multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26449P4MEDIUMCVSS 5.5v13.0v14.0+4 more2025-09-04
CVE-2025-26449 [MEDIUM] CWE-400 CVE-2025-26449: In multiple locations, there is a possible permanent denial of service due to resource exhaustion. T
In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32926P4MEDIUMCVSS 5.5vAndroid kernel2024-06-13
CVE-2024-32926 [MEDIUM] CWE-203 CVE-2024-32926: there is a possible information disclosure due to side channel information disclosure. This could le
there is a possible information disclosure due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0069P4MEDIUMCVSS 5.5v14.0v142026-06-01
CVE-2026-0069 [MEDIUM] CWE-400 CVE-2026-0069: In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource ex
In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0067P4MEDIUMCVSS 5.5v14.0v15.0+8 more2026-06-01
CVE-2026-0067 [MEDIUM] CVE-2026-0067: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent de
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0018P4MEDIUMCVSS 5.5v15.0v16.0+6 more2026-06-01
CVE-2026-0018 [MEDIUM] CWE-20 CVE-2026-0018: In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of
In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0042P4MEDIUMCVSS 5.5v14.0v15.0+8 more2026-06-01
CVE-2026-0042 [MEDIUM] CWE-400 CVE-2026-0042: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of servic
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0074P4MEDIUMCVSS 5.5v14.0v15.0+8 more2026-06-01
CVE-2026-0074 [MEDIUM] CWE-400 CVE-2026-0074: In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due t
In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21290P4MEDIUMCVSS 5.5v11.0v12.0+6 more2023-08-14
CVE-2023-21290 [MEDIUM] CWE-362 CVE-2023-21290: In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a rac
In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48569P4MEDIUMCVSS 5.5v16.0v16-qpr22025-12-08
CVE-2025-48569 [MEDIUM] CWE-770 CVE-2025-48569: In multiple locations, there is a possible permanent denial of service due to resource exhaustion. T
In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-25502P4MEDIUMCVSS 5.5v8.1v9.0+2 more2021-11-05
CVE-2021-25502 [MEDIUM] CWE-269 CVE-2021-25502: A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-20
A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.
nvd
CVE-2023-20914P4MEDIUMCVSS 5.5v11.0vAndroid-112023-05-15
CVE-2023-20914 [MEDIUM] CWE-312 CVE-2023-20914: In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a
In onSetRuntimePermissionGrantStateByDeviceAdmin of AdminRestrictedPermissionsUtils.java, there is a possible way for the work profile to read SMS messages due to a permissions bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro
nvd