Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 302 of 339
CVE-2022-47336P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-04-11
CVE-2022-47336 [MEDIUM] CWE-120 CVE-2022-47336: In telecom service, there is a missing permission check. This could lead to local denial of service
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
nvd
CVE-2022-47464P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-04-11
CVE-2022-47464 [MEDIUM] CWE-120 CVE-2022-47464: In telecom service, there is a missing permission check. This could lead to local denial of service
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
nvd
CVE-2022-47466P4MEDIUMCVSS 5.5v10.0v11.02023-04-11
CVE-2022-47466 [MEDIUM] CWE-476 CVE-2022-47466: In telecom service, there is a missing permission check. This could lead to local denial of service
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
nvd
CVE-2022-47465P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-04-11
CVE-2022-47465 [MEDIUM] CWE-476 CVE-2022-47465: In vdsp service, there is a missing permission check. This could lead to local denial of service in
In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.
nvd
CVE-2022-47467P4MEDIUMCVSS 5.5v10.0v11.02023-04-11
CVE-2022-47467 [MEDIUM] CWE-476 CVE-2022-47467: In telecom service, there is a missing permission check. This could lead to local denial of service
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
nvd
CVE-2022-47463P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-04-11
CVE-2022-47463 [MEDIUM] CWE-120 CVE-2022-47463: In telecom service, there is a missing permission check. This could lead to local denial of service
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
nvd
CVE-2022-47356P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47356 [MEDIUM] CWE-400 CVE-2022-47356: In log service, there is a missing permission check. This could lead to local denial of service in l
In log service, there is a missing permission check. This could lead to local denial of service in log service.
nvd
CVE-2022-47354P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47354 [MEDIUM] CWE-400 CVE-2022-47354: In log service, there is a missing permission check. This could lead to local denial of service in l
In log service, there is a missing permission check. This could lead to local denial of service in log service.
nvd
CVE-2022-47355P4MEDIUMCVSS 5.5v10.0v11.0+1 more2023-02-12
CVE-2022-47355 [MEDIUM] CWE-400 CVE-2022-47355: In log service, there is a missing permission check. This could lead to local denial of service in l
In log service, there is a missing permission check. This could lead to local denial of service in log service.
nvd
CVE-2009-2656P4MEDIUMCVSS 5.0v1.0v1.1+1 more2009-08-03
CVE-2009-2656 [MEDIUM] CVE-2009-2656: Unspecified vulnerability in the com.android.phone process in Android 1.0, 1.1, and 1.5 allows remot
Unspecified vulnerability in the com.android.phone process in Android 1.0, 1.1, and 1.5 allows remote attackers to cause a denial of service (network disconnection) via a crafted SMS message, as demonstrated by Collin Mulliner and Charlie Miller at Black Hat USA 2009.
nvd
CVE-2009-3698P4MEDIUMCVSS 4.3≤ 1.52009-10-14
CVE-2009-3698 [MEDIUM] CVE-2009-3698: An unspecified function in the Dalvik API in Android 1.5 and earlier allows remote attackers to caus
An unspecified function in the Dalvik API in Android 1.5 and earlier allows remote attackers to cause a denial of service (system process restart) via a crafted application, possibly a related issue to CVE-2009-2656.
nvd
CVE-2017-0532P4MEDIUMCVSS 4.7≤ 7.1.12017-03-08
CVE-2017-0532 [MEDIUM] CWE-200 CVE-2017-0532: An information disclosure vulnerability in the MediaTek video codec driver could enable a local mali
An information disclosure vulnerability in the MediaTek video codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-32370398. References: M-ALPS03069985.
nvd
CVE-2016-8472P4MEDIUMCVSS 4.7≤ 7.1.02017-01-12
CVE-2016-8472 [MEDIUM] CWE-200 CVE-2016-8472: An information disclosure vulnerability in the MediaTek driver could enable a local malicious applic
An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-31531758. References: MT-ALPS02961384.
nvd
CVE-2016-8470P4MEDIUMCVSS 4.7≤ 7.1.02017-01-12
CVE-2016-8470 [MEDIUM] CWE-200 CVE-2016-8470: An information disclosure vulnerability in the MediaTek driver could enable a local malicious applic
An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-31528889. References: MT-ALPS02961395.
nvd
CVE-2016-8471P4MEDIUMCVSS 4.7≤ 7.1.02017-01-12
CVE-2016-8471 [MEDIUM] CWE-200 CVE-2016-8471: An information disclosure vulnerability in the MediaTek driver could enable a local malicious applic
An information disclosure vulnerability in the MediaTek driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-31528890. References: MT-ALPS02961380.
nvd
CVE-2022-39134P4MEDIUMCVSS 4.7v10.0v11.0+1 more2022-12-06
CVE-2022-39134 [MEDIUM] CWE-362 CVE-2022-39134: In audio driver, there is a use after free due to a race condition. This could lead to local denial
In audio driver, there is a use after free due to a race condition. This could lead to local denial of service in kernel.
nvd
CVE-2025-20765P4MEDIUMCVSS 4.7v14.0v15.0+1 more2025-12-02
CVE-2025-20765 [MEDIUM] CWE-362 CVE-2025-20765: In aee daemon, there is a possible system crash due to a race condition. This could lead to local de
In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10190802; Issue ID: MSV-4833.
nvd
CVE-2022-20497P4MEDIUMCVSS 4.6v12.0v12.1+2 more2022-12-13
CVE-2022-20497 [MEDIUM] CWE-200 CVE-2022-20497: In updatePublicMode of NotificationLockscreenUserManagerImpl.java, there is a possible way to reveal
In updatePublicMode of NotificationLockscreenUserManagerImpl.java, there is a possible way to reveal sensitive notifications on the lockscreen due to an incorrect state transition. This could lead to local information disclosure with physical access required and an app that runs above the lockscreen, with no additional execution privileges needed. U
nvd
CVE-2022-39900P4MEDIUMCVSS 4.6v11.0v12.0+1 more2022-12-08
CVE-2022-39900 [MEDIUM] CWE-284 CVE-2022-39900: Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical
Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access contents of all toast generated in the application installed in Secure Folder through Nice Catch.
nvd
CVE-2020-25048P4MEDIUMCVSS 4.6v10.02020-08-31
CVE-2020-25048 [MEDIUM] CWE-306 CVE-2020-25048: An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Loc
An issue was discovered on Samsung mobile devices with Q(10.0) (with ONEUI 2.1) software. In the Lockscreen state, the Quick Share feature allows unauthenticated downloads, aka file injection. The Samsung ID is SVE-2020-17760 (August 2020).
nvd