Google Android vulnerabilities
9,713 known vulnerabilities affecting google/android.
Total CVEs
9,713
CISA KEV
49
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5220MEDIUM3343LOW265UNKNOWN2
Vulnerabilities
Page 29 of 486
CVE-2025-47328HIGHCVSS 7.52025-09-01
CVE-2025-47328 [HIGH] CVE-2025-47328: Closed-source component
Android Security Bulletin 2025-09-01
CVE: CVE-2025-47328
Severity: HIGH
Component: Closed-source component
References: A-421905306
*
android
CVE-2025-21477HIGHCVSS 7.52025-09-01
CVE-2025-21477 [HIGH] CVE-2025-21477: Closed-source component
Android Security Bulletin 2025-09-01
CVE: CVE-2025-21477
Severity: HIGH
Component: Closed-source component
References: A-394100233
*
android
CVE-2025-21481HIGHCVSS 7.82025-09-01
CVE-2025-21481 [HIGH] CVE-2025-21481: Closed-source component
Android Security Bulletin 2025-09-01
CVE: CVE-2025-21481
Severity: HIGH
Component: Closed-source component
References: A-400450230
*
android
CVE-2025-27052HIGHCVSS 7.82025-09-01
CVE-2025-27052 [HIGH] CVE-2025-27052: Closed-source component
Android Security Bulletin 2025-09-01
CVE: CVE-2025-27052
Severity: HIGH
Component: Closed-source component
References: A-409039825
*
android
CVE-2025-46710HIGHCVSS 5.72025-09-01
CVE-2025-46710 [MEDIUM] CVE-2025-46710: PowerVR-GPU
Android Security Bulletin 2025-09-01
CVE: CVE-2025-46710
Severity: HIGH
Component: PowerVR-GPU
References: A-382329905
*
android
CVE-2025-27032HIGHCVSS 7.82025-09-01
CVE-2025-27032 [HIGH] CVE-2025-27032: Closed-source component
Android Security Bulletin 2025-09-01
CVE: CVE-2025-27032
Severity: HIGH
Component: Closed-source component
References: A-400449519
*
android
CVE-2025-25179HIGHCVSS 7.82025-09-01
CVE-2025-25179 [HIGH] CVE-2025-25179: PowerVR-GPU
Android Security Bulletin 2025-09-01
CVE: CVE-2025-25179
Severity: HIGH
Component: PowerVR-GPU
References: A-383186226
*
android
CVE-2025-21484HIGHCVSS 8.22025-09-01
CVE-2025-21484 [HIGH] CVE-2025-21484: Closed-source component
Android Security Bulletin 2025-09-01
CVE: CVE-2025-21484
Severity: HIGH
Component: Closed-source component
References: A-400449949
*
android
CVE-2025-21464HIGHCVSS 6.52025-09-01
CVE-2025-21464 [MEDIUM] CVE-2025-21464: Closed-source component
Android Security Bulletin 2025-09-01
CVE: CVE-2025-21464
Severity: HIGH
Component: Closed-source component
References: A-394100533
*
android
CVE-2025-27065HIGHCVSS 7.52025-09-01
CVE-2025-27065 [HIGH] CVE-2025-27065: Closed-source component
Android Security Bulletin 2025-09-01
CVE: CVE-2025-27065
Severity: HIGH
Component: Closed-source component
References: A-415772924
*
android
CVE-2024-7881HIGHCVSS 5.12025-09-01
CVE-2024-7881 [MEDIUM] CVE-2024-7881: CPU
Android Security Bulletin 2025-09-01
CVE: CVE-2024-7881
Severity: HIGH
Component: CPU
References: A-361573291
*
android
CVE-2025-20707MEDIUMCVSS 6.7v13.0v14.0+1 more2025-09-01
CVE-2025-20707 [MEDIUM] CWE-416 CVE-2025-20707: In geniezone, there is a possible memory corruption due to use after free. This could lead to local
In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09924201; Issue ID: MSV-3820.
nvd
CVE-2025-22408CRITICALCVSS 9.8v15.0v152025-08-26
CVE-2025-22408 [CRITICAL] CWE-416 CVE-2025-22408: In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a us
In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-22403CRITICALCVSS 9.8v15.0v152025-08-26
CVE-2025-22403 [CRITICAL] CWE-416 CVE-2025-22403: In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code
In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-0075CRITICALCVSS 9.8v15.0v152025-08-26
CVE-2025-0075 [CRITICAL] CWE-416 CVE-2025-0075: In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary co
In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-0074CRITICALCVSS 9.8v15.0v152025-08-26
CVE-2025-0074 [CRITICAL] CWE-416 CVE-2025-0074: In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code d
In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-22409HIGHCVSS 8.4v15.0v152025-08-26
CVE-2025-22409 [HIGH] CWE-416 CVE-2025-22409: In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a
In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-0093HIGHCVSS 7.5v12.0v12.1+8 more2025-08-26
CVE-2025-0093 [HIGH] CWE-732 CVE-2025-0093: In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to
In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvdandroid
CVE-2023-21125HIGHCVSS 8.0v12.0v12.1+2 more2025-08-26
CVE-2023-21125 [HIGH] CWE-416 CVE-2023-21125: In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use a
In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-0084HIGHCVSS 8.8v13.0v14.0+4 more2025-08-26
CVE-2025-0084 [HIGH] CWE-416 CVE-2025-0084: In multiple locations, there is a possible out of bounds write due to a use after free. This could l
In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid