cbcvebase.

Google Android vulnerabilities

9,713 known vulnerabilities affecting google/android.

Total CVEs
9,713
CISA KEV
49
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5220MEDIUM3343LOW265UNKNOWN2

Vulnerabilities

Page 29 of 486
CVE-2025-47328HIGHCVSS 7.52025-09-01
CVE-2025-47328 [HIGH] CVE-2025-47328: Closed-source component Android Security Bulletin 2025-09-01 CVE: CVE-2025-47328 Severity: HIGH Component: Closed-source component References: A-421905306 *
android
CVE-2025-21477HIGHCVSS 7.52025-09-01
CVE-2025-21477 [HIGH] CVE-2025-21477: Closed-source component Android Security Bulletin 2025-09-01 CVE: CVE-2025-21477 Severity: HIGH Component: Closed-source component References: A-394100233 *
android
CVE-2025-21481HIGHCVSS 7.82025-09-01
CVE-2025-21481 [HIGH] CVE-2025-21481: Closed-source component Android Security Bulletin 2025-09-01 CVE: CVE-2025-21481 Severity: HIGH Component: Closed-source component References: A-400450230 *
android
CVE-2025-27052HIGHCVSS 7.82025-09-01
CVE-2025-27052 [HIGH] CVE-2025-27052: Closed-source component Android Security Bulletin 2025-09-01 CVE: CVE-2025-27052 Severity: HIGH Component: Closed-source component References: A-409039825 *
android
CVE-2025-46710HIGHCVSS 5.72025-09-01
CVE-2025-46710 [MEDIUM] CVE-2025-46710: PowerVR-GPU Android Security Bulletin 2025-09-01 CVE: CVE-2025-46710 Severity: HIGH Component: PowerVR-GPU References: A-382329905 *
android
CVE-2025-27032HIGHCVSS 7.82025-09-01
CVE-2025-27032 [HIGH] CVE-2025-27032: Closed-source component Android Security Bulletin 2025-09-01 CVE: CVE-2025-27032 Severity: HIGH Component: Closed-source component References: A-400449519 *
android
CVE-2025-25179HIGHCVSS 7.82025-09-01
CVE-2025-25179 [HIGH] CVE-2025-25179: PowerVR-GPU Android Security Bulletin 2025-09-01 CVE: CVE-2025-25179 Severity: HIGH Component: PowerVR-GPU References: A-383186226 *
android
CVE-2025-21484HIGHCVSS 8.22025-09-01
CVE-2025-21484 [HIGH] CVE-2025-21484: Closed-source component Android Security Bulletin 2025-09-01 CVE: CVE-2025-21484 Severity: HIGH Component: Closed-source component References: A-400449949 *
android
CVE-2025-21464HIGHCVSS 6.52025-09-01
CVE-2025-21464 [MEDIUM] CVE-2025-21464: Closed-source component Android Security Bulletin 2025-09-01 CVE: CVE-2025-21464 Severity: HIGH Component: Closed-source component References: A-394100533 *
android
CVE-2025-27065HIGHCVSS 7.52025-09-01
CVE-2025-27065 [HIGH] CVE-2025-27065: Closed-source component Android Security Bulletin 2025-09-01 CVE: CVE-2025-27065 Severity: HIGH Component: Closed-source component References: A-415772924 *
android
CVE-2024-7881HIGHCVSS 5.12025-09-01
CVE-2024-7881 [MEDIUM] CVE-2024-7881: CPU Android Security Bulletin 2025-09-01 CVE: CVE-2024-7881 Severity: HIGH Component: CPU References: A-361573291 *
android
CVE-2025-20707MEDIUMCVSS 6.7v13.0v14.0+1 more2025-09-01
CVE-2025-20707 [MEDIUM] CWE-416 CVE-2025-20707: In geniezone, there is a possible memory corruption due to use after free. This could lead to local In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09924201; Issue ID: MSV-3820.
nvd
CVE-2025-22408CRITICALCVSS 9.8v15.0v152025-08-26
CVE-2025-22408 [CRITICAL] CWE-416 CVE-2025-22408: In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a us In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-22403CRITICALCVSS 9.8v15.0v152025-08-26
CVE-2025-22403 [CRITICAL] CWE-416 CVE-2025-22403: In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-0075CRITICALCVSS 9.8v15.0v152025-08-26
CVE-2025-0075 [CRITICAL] CWE-416 CVE-2025-0075: In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary co In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-0074CRITICALCVSS 9.8v15.0v152025-08-26
CVE-2025-0074 [CRITICAL] CWE-416 CVE-2025-0074: In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code d In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-22409HIGHCVSS 8.4v15.0v152025-08-26
CVE-2025-22409 [HIGH] CWE-416 CVE-2025-22409: In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-0093HIGHCVSS 7.5v12.0v12.1+8 more2025-08-26
CVE-2025-0093 [HIGH] CWE-732 CVE-2025-0093: In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvdandroid
CVE-2023-21125HIGHCVSS 8.0v12.0v12.1+2 more2025-08-26
CVE-2023-21125 [HIGH] CWE-416 CVE-2023-21125: In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use a In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2025-0084HIGHCVSS 8.8v13.0v14.0+4 more2025-08-26
CVE-2025-0084 [HIGH] CWE-416 CVE-2025-0084: In multiple locations, there is a possible out of bounds write due to a use after free. This could l In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid