Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 27 of 339
CVE-2018-9459P3HIGHCVSS 8.8v6.0v6.0.1+5 more2018-11-06
CVE-2018-9459 [HIGH] CWE-22 CVE-2018-9459: In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible
In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privilege due to a path traversal error. This could lead to a remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 A
nvd
CVE-2017-0877P3HIGHCVSS 8.8v6.02017-12-06
CVE-2017-0877 [HIGH] CWE-20 CVE-2017-0877: A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Ver
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-66372937.
nvd
CVE-2017-0878P3HIGHCVSS 8.8v8.02017-12-06
CVE-2017-0878 [HIGH] CWE-20 CVE-2017-0878: A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Ve
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 8.0. Android ID A-65186291.
nvd
CVE-2017-0872P3HIGHCVSS 8.8v7.0v7.1.1+2 more2017-12-06
CVE-2017-0872 [HIGH] CWE-20 CVE-2017-0872: A remote code execution vulnerability in the Android media framework (libskia). Product: Android. Ve
A remote code execution vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65290323.
nvd
CVE-2017-0876P3HIGHCVSS 8.8v6.02017-12-06
CVE-2017-0876 [HIGH] CWE-20 CVE-2017-0876: A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Ver
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-64964675.
nvd
CVE-2017-13151P3HIGHCVSS 8.8v6.0v6.0.1+4 more2017-12-06
CVE-2017-13151 [HIGH] CWE-682 CVE-2017-13151: A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. V
A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-63874456.
nvd
CVE-2017-13176P3HIGHCVSS 8.8v5.1.1v6.0+6 more2018-01-12
CVE-2017-13176 [HIGH] CWE-20 CVE-2017-13176: In the parseURL function of URLStreamHandler, there is improper input validation of the host field.
In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privilege that could enable bypassing user interaction requirements with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7
nvd
CVE-2019-20783P3CRITICALCVSS 9.1v7.0v7.1+3 more2020-04-17
CVE-2019-20783 [CRITICAL] CVE-2019-20783: An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (North Amer
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (North America CDMA) software. The LTE protocol implementation allows a bypass of AKA (Authentication and Key Agreement). The LG ID is LVE-SMP-180014 (February 2019).
nvd
CVE-2020-0160P3HIGHCVSS 8.8v10.0vAndroid-102020-06-11
CVE-2020-0160 [HIGH] CWE-20 CVE-2020-0160: In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bo
In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-124771364
nvd
CVE-2022-30711P3CRITICALCVSS 9.1v10.0v11.0+1 more2022-06-07
CVE-2022-30711 [CRITICAL] CWE-20 CVE-2022-30711: Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to l
Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
nvd
CVE-2022-30710P3CRITICALCVSS 9.1v10.0v11.0+1 more2022-06-07
CVE-2022-30710 [CRITICAL] CWE-20 CVE-2022-30710: Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to
Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
nvd
CVE-2022-30713P3CRITICALCVSS 9.1v10.0v11.0+1 more2022-06-07
CVE-2022-30713 [CRITICAL] CWE-20 CVE-2022-30713: Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to
Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
nvd
CVE-2011-3874P3CRITICALCVSS 9.3v2.2v2.2.1+8 more2012-01-27
CVE-2011-3874 [CRITICAL] CWE-119 CVE-2011-3874: Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 al
Stack-based buffer overflow in libsysutils in Android 2.2.x through 2.2.2 and 2.3.x through 2.3.6 allows user-assisted remote attackers to execute arbitrary code via an application that calls the FrameworkListener::dispatchCommand method with the wrong number of arguments, as demonstrated by zergRush to trigger a use-after-free error.
nvd
CVE-2018-9555P3HIGHCVSS 8.8v7.0v7.1.1+4 more2018-12-06
CVE-2018-9555 [HIGH] CWE-787 CVE-2018-9555: In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds c
In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android
nvd
CVE-2021-0968P3HIGHCVSS 8.8v9.0v10.0+3 more2021-12-15
CVE-2021-0968 [HIGH] CWE-190 CVE-2021-0968: In osi_malloc and osi_calloc of allocator.cc, there is a possible out of bounds write due to an inte
In osi_malloc and osi_calloc of allocator.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-197868577
nvd
CVE-2019-2005P3HIGHCVSS 8.8v8.0v8.1+2 more2019-06-19
CVE-2019-2005 [HIGH] CWE-862 CVE-2019-2005: In onPermissionGrantResult of GrantPermissionsActivity.java, there is a possible incorrectly granted
In onPermissionGrantResult of GrantPermissionsActivity.java, there is a possible incorrectly granted permission due to a missing permission check. This could lead to local escalation of privilege on a locked device with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.
nvd
CVE-2022-20469P3HIGHCVSS 8.8v10.0v11.0+4 more2022-12-13
CVE-2022-20469 [HIGH] CWE-787 CVE-2022-20469: In avct_lcb_msg_asmbl of avct_lcb_act.cc, there is a possible out of bounds write due to a missing b
In avct_lcb_msg_asmbl of avct_lcb_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-1
nvd
CVE-2021-0965P3HIGHCVSS 8.8v9.0v10.0+3 more2021-12-15
CVE-2021-0965 [HIGH] CWE-862 CVE-2021-0965: In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's
In AndroidManifest.xml of Settings, there is a possible pairing of a Bluetooth device without user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android
nvd
CVE-2025-36901P3HIGHCVSS 8.8vAndroid kernel2025-09-04
CVE-2025-36901 [HIGH] CWE-269 CVE-2025-36901: WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-39646
WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.
nvd
CVE-2023-21115P3HIGHCVSS 8.8v11.0v12.0+2 more2023-06-15
CVE-2023-21115 [HIGH] CWE-327 CVE-2023-21115: In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due
In btm_sec_encrypt_change of btm_sec.cc, there is a possible way to downgrade the link key type due to improperly used crypto. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-2
nvd