Google Android vulnerabilities
9,713 known vulnerabilities affecting google/android.
Total CVEs
9,713
CISA KEV
49
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5216MEDIUM3347LOW265UNKNOWN2
Vulnerabilities
Page 3 of 486
CVE-2026-0070MEDIUMCVSS 5.5v14.0v15.0+5 more2026-06-01
CVE-2026-0070 [MEDIUM] CWE-20 CVE-2026-0070: In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system c
In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26418MEDIUMCVSS 5.9v14.0v15.0+2 more2026-06-01
CVE-2025-26418 [MEDIUM] CWE-862 CVE-2025-26418: In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass t
In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0060MEDIUMCVSS 5.5v14.0v15.0+5 more2026-06-01
CVE-2026-0060 [MEDIUM] CVE-2026-0060: In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persis
In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0080MEDIUMCVSS 6.5v16-qpr2v16+2 more2026-06-01
CVE-2026-0080 [MEDIUM] CWE-190 CVE-2026-0080: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0061MEDIUMCVSS 5.9v14.0v15.0+5 more2026-06-01
CVE-2026-0061 [MEDIUM] CWE-1021 CVE-2026-0061: In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a
In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0051MEDIUMCVSS 6.5v14.0v15.0+5 more2026-06-01
CVE-2026-0051 [MEDIUM] CWE-20 CVE-2026-0051: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0055MEDIUMCVSS 6.2v14.0v15.0+5 more2026-06-01
CVE-2026-0055 [MEDIUM] CWE-22 CVE-2026-0055: In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Pol
In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0044MEDIUMCVSS 6.5v14.0v15.0+5 more2026-06-01
CVE-2026-0044 [MEDIUM] CWE-190 CVE-2026-0044: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0086MEDIUMCVSS 6.8v16-qpr22026-06-01
CVE-2026-0086 [MEDIUM] CWE-269 CVE-2026-0086: In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due
In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-28581MEDIUMCVSS 4.0v14.0v15.0+5 more2026-06-01
CVE-2026-28581 [MEDIUM] CWE-476 CVE-2026-28581: In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emer
In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileges needed. User interaction is null for exploitation.
nvd
CVE-2025-22426MEDIUMCVSS 5.9v14.0v15.0+5 more2026-06-01
CVE-2025-22426 [MEDIUM] CWE-284 CVE-2025-22426: In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to
In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0074MEDIUMCVSS 5.5v14.0v15.0+5 more2026-06-01
CVE-2026-0074 [MEDIUM] CWE-400 CVE-2026-0074: In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due t
In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0052MEDIUMCVSS 6.5v14.0v15.0+5 more2026-06-01
CVE-2026-0052 [MEDIUM] CWE-190 CVE-2026-0052: In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0085MEDIUMCVSS 5.5v16-qpr2v16+2 more2026-06-01
CVE-2026-0085 [MEDIUM] CWE-20 CVE-2026-0085: In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact
In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-28578MEDIUMCVSS 5.5v14.0v15.0+5 more2026-06-01
CVE-2026-28578 [MEDIUM] CWE-20 CVE-2026-28578: In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistenc
In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-28586LOWCVSS 3.3v14.0v15.0+5 more2026-06-01
CVE-2026-28586 [LOW] CWE-269 CVE-2026-28586: In multiple functions of AppOpsService.java, there is a possible missing permission check due to a p
In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48616LOWCVSS 3.3v14.0v15.0+5 more2026-06-01
CVE-2025-48616 [LOW] CVE-2025-48616: In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode
In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0056LOWCVSS 3.3v14.0v15.0+5 more2026-06-01
CVE-2026-0056 [LOW] CWE-120 CVE-2026-0056: In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds che
In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0050LOWCVSS 3.3v15.0v16.0+3 more2026-06-01
CVE-2026-0050 [LOW] CWE-269 CVE-2026-0050: In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosu
In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0016LOWCVSS 3.3v16.0v16-qpr2+1 more2026-06-01
CVE-2026-0016 [LOW] CWE-269 CVE-2026-0016: In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to ov
In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd