Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 266 of 339
CVE-2022-20266P4MEDIUMCVSS 5.0v13.0vAndroid-132022-08-12
CVE-2022-20266 [MEDIUM] CWE-20 CVE-2022-20266: In Companion, there is a possible way to keep a service running with elevated importance without sho
In Companion, there is a possible way to keep a service running with elevated importance without showing foreground service notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Andr
nvd
CVE-2025-48562P4MEDIUMCVSS 5.0v13.0v14.0+6 more2025-09-04
CVE-2025-48562 [MEDIUM] CWE-209 CVE-2025-48562: In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a log
In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-48551P4MEDIUMCVSS 5.0v13.0v14.0+6 more2025-09-04
CVE-2025-48551 [MEDIUM] CWE-441 CVE-2025-48551: In multiple locations, there is a possible leak of an image across the Android User isolation bounda
In multiple locations, there is a possible leak of an image across the Android User isolation boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2026-0140P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0140 CVE-2026-0140: In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This
In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2026-0134P4UNKNOWNvAndroid kernel2026-06-16
CVE-2026-0134 CVE-2026-0134: In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset
In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-5310P4MEDIUMCVSS 4.3v4.4.4v5.0+3 more2016-01-06
CVE-2015-5310 [MEDIUM] CWE-200 CVE-2015-5310: The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in respon
The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers to inject arbitrary broadcast or multicast packets or cause a denial of service (ignored packets) via a WNM Sleep Mode response.
nvd
CVE-2017-3750P4MEDIUMCVSS 6.4≤ 5.1.12017-06-29
CVE-2017-3750 [MEDIUM] CVE-2017-3750: On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be back
On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3749.
nvd
CVE-2018-21068P4MEDIUMCVSS 6.2v8.02020-04-08
CVE-2018-21068 [MEDIUM] CWE-20 CVE-2018-21068: An issue was discovered on Samsung mobile devices with O(8.0) software. Execution of an application
An issue was discovered on Samsung mobile devices with O(8.0) software. Execution of an application in a locked Secure Folder can occur without a password via a split screen. The Samsung ID is SVE-2018-11669 (July 2018).
nvd
CVE-2018-21048P4MEDIUMCVSS 6.2v8.0v8.12020-04-08
CVE-2018-21048 [MEDIUM] CWE-200 CVE-2018-21048: An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Notification leak
An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Notification leak on a locked device in Standalone Dex mode. The Samsung ID is SVE-2018-12925 (November 2018).
nvd
CVE-2016-0812P4MEDIUMCVSS 6.1v5.1v5.1.0+3 more2016-02-07
CVE-2016-0812 [MEDIUM] CWE-264 CVE-2016-0812: The interceptKeyBeforeDispatching function in policy/src/com/android/internal/policy/impl/PhoneWindo
The interceptKeyBeforeDispatching function in policy/src/com/android/internal/policy/impl/PhoneWindowManager.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.0 before 2016-02-01 does not properly check for setup completion, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete
nvd
CVE-2016-2421P4MEDIUMCVSS 6.1v5.1v5.1.0+2 more2016-04-18
CVE-2016-2421 [MEDIUM] CWE-264 CVE-2016-2421: Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 2016-04-01 allows physically proximate att
Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 2016-04-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 26154410.
nvd
CVE-2018-9437P4MEDIUMCVSS 5.5v6.0v6.0.1+5 more2018-11-06
CVE-2018-9437 [MEDIUM] CWE-125 CVE-2018-9437: In getstring of ID3.cpp there is a possible out-of-bounds read due to a missing bounds check. This c
In getstring of ID3.cpp there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Andro
nvd
CVE-2020-0379P4MEDIUMCVSS 5.7v8.0v8.1+4 more2020-09-17
CVE-2020-0379 [MEDIUM] CVE-2020-0379: In the Bluetooth service, there is a possible spoofing attack due to a logic error. This could lead
In the Bluetooth service, there is a possible spoofing attack due to a logic error. This could lead to remote information disclosure of sensitive information with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-150156492
nvd
CVE-2016-3897P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-09-11
CVE-2016-3897 [MEDIUM] CWE-200 CVE-2016-3897: The WifiEnterpriseConfig class in net/wifi/WifiEnterpriseConfig.java in Wi-Fi in Android 4.x before
The WifiEnterpriseConfig class in net/wifi/WifiEnterpriseConfig.java in Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 includes a password in the return value of a toString method call, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 25624963.
nvd
CVE-2017-0414P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-02-08
CVE-2017-0414 [MEDIUM] CWE-200 CVE-2017-0414: An information disclosure vulnerability in AOSP Messaging could enable a local malicious application
An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 6.0, 6.0
nvd
CVE-2017-0494P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-03-08
CVE-2017-0494 [MEDIUM] CWE-200 CVE-2017-0494: An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a spe
An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32764144.
nvd
CVE-2017-13279P4MEDIUMCVSS 5.5v6.0v6.0.1+5 more2018-04-04
CVE-2017-13279 [MEDIUM] CWE-834 CVE-2017-13279: In M3UParser::parse of M3UParser.cpp, there is a memory resource exhaustion due to a large loop of p
In M3UParser::parse of M3UParser.cpp, there is a memory resource exhaustion due to a large loop of pushing items into a vector. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-683
nvd
CVE-2017-0547P4MEDIUMCVSS 5.5v4.0v4.0.1+26 more2017-04-07
CVE-2017-0547 [MEDIUM] CWE-200 CVE-2017-0547: An information disclosure vulnerability in libmedia in Mediaserver could enable a local malicious ap
An information disclosure vulnerability in libmedia in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it is a general bypass for operating system protections that isolate application data from other applications. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
nvd
CVE-2014-9892P4MEDIUMCVSS 5.5≤ 6.0.12016-08-06
CVE-2014-9892 [MEDIUM] CWE-200 CVE-2014-9892: The snd_compr_tstamp function in sound/core/compress_offload.c in the Linux kernel through 4.7, as u
The snd_compr_tstamp function in sound/core/compress_offload.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize a timestamp data structure, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28770164 and Qualcomm i
nvd
CVE-2016-3923P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-3923 [MEDIUM] CWE-284 CVE-2016-3923: The Accessibility services in Android 7.0 before 2016-10-01 mishandle motion events, which allows at
The Accessibility services in Android 7.0 before 2016-10-01 mishandle motion events, which allows attackers to conduct touchjacking attacks and consequently gain privileges via a crafted application, aka internal bug 30647115.
nvd