Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 293 of 339
CVE-2022-20544P4MEDIUMCVSS 4.4v13.0vAndroid-132022-12-16
CVE-2022-20544 [MEDIUM] CWE-862 CVE-2022-20544: In onOptionsItemSelected of ManageApplications.java, there is a possible bypass of profile owner res
In onOptionsItemSelected of ManageApplications.java, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238745070
nvd
CVE-2025-26427P4MEDIUMCVSS 4.4v13.0v14.0+2 more2025-09-04
CVE-2025-26427 [MEDIUM] CWE-24 CVE-2025-26427: In multiple locations, there is a possible Android/data access due to a path traversal error. This c
In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2024-27225P4MEDIUMCVSS 4.4v13.0v132024-03-11
CVE-2024-27225 [MEDIUM] CWE-120 CVE-2024-27225: In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer o
In sendHciCommand of bluetooth_hci.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20255P4MEDIUMCVSS 4.4v13.0vAndroid-132022-08-12
CVE-2022-20255 [MEDIUM] CWE-862 CVE-2022-20255: In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing
In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222687217
nvd
CVE-2025-26420P4MEDIUMCVSS 4.4v13.0v14.0+2 more2025-09-04
CVE-2025-26420 [MEDIUM] CWE-281 CVE-2025-26420: In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user i
In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32915P4MEDIUMCVSS 4.3vAndroid kernel2024-06-13
CVE-2024-32915 [MEDIUM] CWE-125 CVE-2024-32915: In CellInfoListParserV2::FillCellInfo() of protocolnetadapter.cpp, there is a possible out of bounds
In CellInfoListParserV2::FillCellInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
nvd
CVE-2022-39899P4MEDIUMCVSS 4.3v10.0v11.0+2 more2022-12-08
CVE-2022-39899 [MEDIUM] CWE-287 CVE-2022-39899: Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release
Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.
nvd
CVE-2025-20744P4MEDIUMCVSS 4.2v13.0v14.0+2 more2025-11-04
CVE-2025-20744 [MEDIUM] CWE-416 CVE-2025-20744: In pda, there is a possible escalation of privilege due to use after free. This could lead to local
In pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10127160; Issue ID: MSV-4542.
nvd
CVE-2025-20743P4MEDIUMCVSS 4.2v14.0v15.0+1 more2025-11-04
CVE-2025-20743 [MEDIUM] CWE-416 CVE-2025-20743: In clkdbg, there is a possible escalation of privilege due to use after free. This could lead to loc
In clkdbg, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10136671; Issue ID: MSV-4651.
nvd
CVE-2025-20745P4MEDIUMCVSS 4.2v13.0v14.0+1 more2025-11-04
CVE-2025-20745 [MEDIUM] CWE-416 CVE-2025-20745: In apusys, there is a possible memory corruption due to use after free. This could lead to local esc
In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10095441; Issue ID: MSV-4294.
nvd
CVE-2025-48526P4MEDIUMCVSS 4.0v13.0v14.0+6 more2025-09-04
CVE-2025-48526 [MEDIUM] CWE-266 CVE-2025-48526: In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to la
In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActivity in another profile due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2017-0488P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-03-08
CVE-2017-0488 [MEDIUM] CWE-20 CVE-2017-0488: A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted
A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34097213.
nvd
CVE-2017-0487P4MEDIUMCVSS 5.5v6.0v6.0.1+3 more2017-03-08
CVE-2017-0487 [MEDIUM] CVE-2017-0487: A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted
A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33751193.
nvd
CVE-2016-3880P4MEDIUMCVSS 5.5v4.0v4.0.1+21 more2016-09-11
CVE-2016-3880 [MEDIUM] CWE-284 CVE-2016-3880: Multiple buffer overflows in rtsp/ASessionDescription.cpp in libstagefright in mediaserver in Androi
Multiple buffer overflows in rtsp/ASessionDescription.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allow remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 25747670.
nvd
CVE-2016-6713P4MEDIUMCVSS 5.5≥ 6.0, ≤ 6.0.1v7.02016-11-25
CVE-2016-6713 [MEDIUM] CWE-284 CVE-2016-6713: A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 bef
A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-30822755.
nvd
CVE-2016-3879P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-09-11
CVE-2016-3879 [MEDIUM] CWE-284 CVE-2016-3879: arm-wt-22k/lib_src/eas_mdls.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x
arm-wt-22k/lib_src/eas_mdls.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows remote attackers to cause a denial of service (NULL pointer dereference, and device hang or reboot) via a crafted media file, aka internal bug 29770686.
nvd
CVE-2016-3878P4MEDIUMCVSS 5.5v6.0v6.0.12016-09-11
CVE-2016-3878 [MEDIUM] CWE-284 CVE-2016-3878: decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-09-01 mishandles the case of decoding
decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-09-01 mishandles the case of decoding zero MBs, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 29493002.
nvd
CVE-2017-0640P4MEDIUMCVSS 5.5v6.0v6.0.1+2 more2017-06-14
CVE-2017-0640 [MEDIUM] CVE-2017-0640: A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33129467.
nvd
CVE-2017-0644P4MEDIUMCVSS 5.5v4.4.4v5.0.2+3 more2017-06-14
CVE-2017-0644 [MEDIUM] CVE-2017-0644: A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1. Android ID: A-35472997.
nvd
CVE-2016-6766P4MEDIUMCVSS 5.5v4.0v4.0.1+24 more2017-01-12
CVE-2016-6766 [MEDIUM] CWE-19 CVE-2016-6766: A denial of service vulnerability in libmedia and libstagefright in Mediaserver could enable an atta
A denial of service vulnerability in libmedia and libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31318219.
nvd