Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 292 of 339
CVE-2022-20196P4MEDIUMCVSS 5.0v12.1vAndroid-12L2022-06-15
CVE-2022-20196 [MEDIUM] CVE-2022-20196: In gallery3d and photos, there is a possible permission bypass due to a confused deputy. This could
In gallery3d and photos, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-201535148
nvd
CVE-2011-3881P4MEDIUMCVSS 4.3fixed in 4.42011-10-25
CVE-2011-3881 [MEDIUM] CWE-79 CVE-2011-3881: WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers
WebKit, as used in Google Chrome before 15.0.874.102 and Android before 4.4, allows remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks via vectors related to (1) the DOMWindow::clear function and use of a selection object, (2) the Object::GetRealNamedPropertyInPrototypeChain function and use of an __proto__ prope
nvd
CVE-2022-20465P4MEDIUMCVSS 4.6v10.0v11.0+4 more2022-11-08
CVE-2022-20465 [MEDIUM] CWE-276 CVE-2022-20465: In dismiss and related functions of KeyguardHostViewController.java and related files, there is a po
In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11
nvd
CVE-2022-20498P4MEDIUMCVSS 4.4v10.0v11.0+4 more2022-12-13
CVE-2022-20498 [MEDIUM] CWE-125 CVE-2022-20498: In fdt_path_offset_namelen of fdt_ro.c, there is a possible out of bounds read due to an incorrect b
In fdt_path_offset_namelen of fdt_ro.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-246465
nvd
CVE-2017-9676P4MEDIUMCVSS 4.7≤ 8.02017-09-21
CVE-2017-9676 [MEDIUM] CWE-200 CVE-2017-9676: In all Qualcomm products with Android releases from CAF using the Linux kernel, potential use after
In all Qualcomm products with Android releases from CAF using the Linux kernel, potential use after free scenarios and race conditions can occur when accessing global static variables without using a lock.
nvd
CVE-2022-20214P4MEDIUMCVSS 4.7v10.0v11.0+2 more2023-01-26
CVE-2022-20214 [MEDIUM] CWE-1021 CVE-2022-20214: In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack.
In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-183411210
nvd
CVE-2021-0443P4MEDIUMCVSS 4.7v8.1v9.0+3 more2021-04-13
CVE-2021-0443 [MEDIUM] CWE-362 CVE-2021-0443: In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly sav
In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly saved screenshot due to a race condition. This could lead to local information disclosure across user profiles with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Andro
nvd
CVE-2020-0282P4MEDIUMCVSS 4.5v11.0vAndroid-112020-09-18
CVE-2020-0282 [MEDIUM] CWE-125 CVE-2020-0282: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to rem
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure. System execution privileges, a Firmware compromise, and User interaction are needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144506224
nvd
CVE-2020-0281P4MEDIUMCVSS 4.5v11.0vAndroid-112020-09-18
CVE-2020-0281 [MEDIUM] CWE-125 CVE-2020-0281: In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to rem
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure. System execution privileges, a Firmware compromise, and User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137857778
nvd
CVE-2020-0008P4MEDIUMCVSS 4.7v8.0v8.1+6 more2020-01-08
CVE-2020-0008 [MEDIUM] CWE-125 CVE-2020-0008: In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds re
In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 A
nvd
CVE-2014-7954P4MEDIUMCVSS 4.6v4.4.42017-07-07
CVE-2014-7954 [MEDIUM] CWE-22 CVE-2014-7954: Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServe
Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4.4 allows physically proximate attackers with a direct connection to the target Android device to upload files outside of the sdcard via a .. (dot dot) in a name parameter of an MTP request.
nvd
CVE-2020-0373P4MEDIUMCVSS 4.7v11.0vAndroid-112020-09-17
CVE-2020-0373 [MEDIUM] CWE-125 CVE-2020-0373: In SoundTriggerHwService, there is a possible out of bounds read due to a race condition. This could
In SoundTriggerHwService, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-146894086
nvd
CVE-2023-21031P4MEDIUMCVSS 4.7v13.0vAndroid-132023-03-24
CVE-2023-21031 [MEDIUM] CWE-125 CVE-2023-21031: In setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This co
In setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-242688355
nvd
CVE-2022-20097P4MEDIUMCVSS 4.7v11.0v12.02022-05-03
CVE-2022-20097 [MEDIUM] CWE-362 CVE-2022-20097: In aee daemon, there is a possible information disclosure due to a race condition. This could lead t
In aee daemon, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06383944; Issue ID: ALPS06383944.
nvd
CVE-2019-11341P4MEDIUMCVSS 4.6v9.02019-10-09
CVE-2019-11341 [MEDIUM] CWE-327 CVE-2019-11341: On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture with
On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowledge. This feature of the Service Mode application is available after entering the *#9900# check code, but is protected by an OTP password. However, this password is created locally and (due to mishandling of cryptography) can be o
nvd
CVE-2020-0473P4MEDIUMCVSS 4.6v11.0vAndroid-112020-12-15
CVE-2020-0473 [MEDIUM] CWE-863 CVE-2020-0473: In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permi
In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing an attacker with physical possession of the device to transfer files to it over Bluetooth, with no additional execution privileges needed. User interaction is not needed for exploi
nvd
CVE-2022-20265P4MEDIUMCVSS 4.6v13.0vAndroid-132022-08-12
CVE-2022-20265 [MEDIUM] CVE-2022-20265: In Settings, there is a possible way to bypass factory reset permissions due to a permissions bypass
In Settings, there is a possible way to bypass factory reset permissions due to a permissions bypass. This could lead to local escalation of privilege with physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-212804898
nvd
CVE-2026-20435P4MEDIUMCVSS 4.6v14.0v15.0+1 more2026-03-02
CVE-2026-20435 [MEDIUM] CWE-522 CVE-2026-20435: In preloader, there is a possible read of device unique identifiers due to a logic error. This could
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10607099; Issue ID: MSV-6118.
nvd
CVE-2009-2348P4MEDIUMCVSS 6.9v1.52009-07-17
CVE-2009-2348 [MEDIUM] CWE-94 CVE-2009-2348: Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permi
Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an application that does not make a permission request before using the camera or microphone.
nvd
CVE-2015-6630P4MEDIUMCVSS 4.3≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-6630 [MEDIUM] CWE-200 CVE-2015-6630: SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to read scree
SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to read screenshots and consequently gain privileges via a crafted application, aka internal bug 19121797.
nvd