Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 28 of 339
CVE-2019-2201P3HIGHCVSS 7.8v8.0v8.1+3 more2019-11-13
CVE-2019-2201 [HIGH] CWE-787 CVE-2019-2201: In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds writ
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 An
nvd
CVE-2015-6608P3CRITICALCVSS 10.0≥ 5.0, < 5.1.1v6.02015-11-03
CVE-2015-6608 [CRITICAL] CWE-119 CVE-2015-6608: mediaserver in Android 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to
mediaserver in Android 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 19779574, 23680780, 23876444, and 23658148, a different vulnerability than CVE-2015-8072 and CVE-2015-8073.
nvd
CVE-2025-48581P3HIGHCVSS 8.4v16.0v162025-09-04
CVE-2025-48581 [HIGH] CWE-754 CVE-2025-48581: In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to
In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-6609P3CRITICALCVSS 10.0≤ 5.1.02015-11-03
CVE-2015-6609 [CRITICAL] CWE-119 CVE-2015-6609: libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute
libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, aka internal bug 22953624.
nvd
CVE-2026-0047P3HIGHCVSS 8.4v16.0v16-qpr22026-03-02
CVE-2026-0047 [HIGH] CWE-280 CVE-2026-0047: In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access pri
In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27213P3HIGHCVSS 8.4v13.0v132024-03-11
CVE-2024-27213 [HIGH] CWE-416 CVE-2024-27213: In BroadcastSystemMessage of servicemgr.cpp, there is a possible Remote Code Execution due to a use
In BroadcastSystemMessage of servicemgr.cpp, there is a possible Remote Code Execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48650P3HIGHCVSS 8.4v14.0v15.0+4 more2026-03-02
CVE-2025-48650 [HIGH] CWE-89 CVE-2025-48650: In multiple locations, there is a possible information disclosure due to SQL injection. This could l
In multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0011P3HIGHCVSS 8.4v14.0v15.0+5 more2026-03-02
CVE-2026-0011 [HIGH] CWE-693 CVE-2026-0011: In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48582P3HIGHCVSS 8.4v14.0v15.0+4 more2026-03-02
CVE-2025-48582 [HIGH] CWE-59 CVE-2025-48582: In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE p
In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an intent redirect. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0029P3HIGHCVSS 8.4vAndroid kernel2026-03-02
CVE-2026-0029 [HIGH] CWE-269 CVE-2026-0029: In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code.
In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-27700P3HIGHCVSS 8.4vAndroid kernel2025-05-27
CVE-2025-27700 [HIGH] CWE-693 CVE-2025-27700: There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to
There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48619P3HIGHCVSS 8.4v14.0v15.0+4 more2026-03-02
CVE-2025-48619 [HIGH] CWE-284 CVE-2025-48619: In multiple functions of ContentProvider.java, there is a possible way for an app with read-only acc
In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate files due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22406P3HIGHCVSS 8.4v15.0v152025-08-26
CVE-2025-22406 [HIGH] CWE-416 CVE-2025-22406: In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due t
In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48574P3HIGHCVSS 8.4v14.0v15.0+4 more2026-03-02
CVE-2025-48574 [HIGH] CWE-862 CVE-2025-48574: In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept dra
In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-22005P3HIGHCVSS 8.4v13.0v132024-03-11
CVE-2024-22005 [HIGH] CWE-787 CVE-2024-22005: there is a possible Authentication Bypass due to improperly used crypto. This could lead to local es
there is a possible Authentication Bypass due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27209P3HIGHCVSS 8.4v13.0v132024-03-11
CVE-2024-27209 [HIGH] CWE-122 CVE-2024-27209: there is a possible out of bounds write due to a heap buffer overflow. This could lead to local esca
there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0008P3HIGHCVSS 8.4v16.0v162026-03-02
CVE-2026-0008 [HIGH] CWE-441 CVE-2026-0008: In multiple locations, there is a possible privilege escalation due to a confused deputy. This coul
In multiple locations, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36899P3HIGHCVSS 8.4vAndroid kernel2025-09-04
CVE-2025-36899 [HIGH] CWE-489 CVE-2025-36899: There is a possible escalation of privilege due to test/debugging code left in a production build. T
There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0123P3HIGHCVSS 8.4vAndroid kernel2026-03-10
CVE-2026-0123 [HIGH] CWE-787 CVE-2026-0123: In EfwApTransport::ProcessRxRing of efw_ap_transport.cc, there is a possible out of bounds write due
In EfwApTransport::ProcessRxRing of efw_ap_transport.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34732P3HIGHCVSS 8.4vAndroid SoC2025-01-28
CVE-2024-34732 [HIGH] CWE-362 CVE-2024-34732: In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race con
In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd