Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 303 of 339
CVE-2017-18646P4MEDIUMCVSS 4.6v6.0v6.0.1+4 more2020-04-08
CVE-2017-18646 [MEDIUM] CWE-287 CVE-2017-18646: An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. An attacker can b
An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. An attacker can bypass the password requirement for tablet user switching by folding the magnetic cover. The Samsung ID is SVE-2017-10602 (December 2017).
nvd
CVE-2022-25820P4MEDIUMCVSS 4.6v11.0v12.02022-03-10
CVE-2022-25820 [MEDIUM] CWE-307 CVE-2022-25820: A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physica
A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password.
nvd
CVE-2025-20652P4MEDIUMCVSS 4.6v13.0v14.0+1 more2025-03-03
CVE-2025-20652 [MEDIUM] CWE-125 CVE-2025-20652: In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to l
In V5 DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291215; Issue ID: MSV-2052.
nvd
CVE-2022-24001P4MEDIUMCVSS 4.6v12.02022-02-11
CVE-2022-24001 [MEDIUM] CWE-200 CVE-2022-24001: Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers
Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel.
nvd
CVE-2024-39431P4MEDIUMCVSS 4.5v12.0v13.0+1 more2024-09-27
CVE-2024-39431 [MEDIUM] CWE-787 CVE-2024-39431: In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This coul
In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed.
nvd
CVE-2021-0996P4MEDIUMCVSS 4.5v12.0vAndroid-122021-12-15
CVE-2021-0996 [MEDIUM] CWE-125 CVE-2021-0996: In nfaHciCallback of HciEventManager.cpp, there is a possible out of bounds read due to a missing bo
In nfaHciCallback of HciEventManager.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over NFC with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-181346545
nvd
CVE-2023-20987P4MEDIUMCVSS 4.5v13.0vAndroid-132023-03-24
CVE-2023-20987 [MEDIUM] CWE-125 CVE-2023-20987: In btm_read_link_quality_complete of btm_acl.cc, there is a possible out of bounds read due to a mis
In btm_read_link_quality_complete of btm_acl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure over Bluetooth with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-260569414
nvd
CVE-2023-21195P4MEDIUMCVSS 4.5v13.0vAndroid-132023-06-28
CVE-2023-21195 [MEDIUM] CWE-125 CVE-2023-21195: In btm_ble_periodic_adv_sync_tx_rcvd of btm_ble_gap.cc, there is a possible out of bounds read due t
In btm_ble_periodic_adv_sync_tx_rcvd of btm_ble_gap.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth, if the firmware were compromised with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13
nvd
CVE-2020-27037P4MEDIUMCVSS 4.4v11.0vAndroid-112020-12-15
CVE-2020-27037 [MEDIUM] CWE-125 CVE-2020-27037: In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds read due to a m
In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153731335
nvd
CVE-2020-27040P4MEDIUMCVSS 4.4v11.0vAndroid-112020-12-15
CVE-2020-27040 [MEDIUM] CWE-125 CVE-2020-27040: In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds read due to a m
In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153731880
nvd
CVE-2020-27053P4MEDIUMCVSS 4.4v11.0vAndroid-112020-12-15
CVE-2020-27053 [MEDIUM] CWE-862 CVE-2020-27053: In broadcastWifiCredentialChanged of ClientModeImpl.java, there is a possible location permission by
In broadcastWifiCredentialChanged of ClientModeImpl.java, there is a possible location permission bypass due to a missing permission check. This could lead to local information disclosure of the WiFi network name with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A
nvd
CVE-2022-20035P4MEDIUMCVSS 4.4v10.0v11.02022-02-09
CVE-2022-20035 [MEDIUM] CWE-416 CVE-2022-20035: In vcu driver, there is a possible information disclosure due to a use after free. This could lead t
In vcu driver, there is a possible information disclosure due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171675; Issue ID: ALPS06171675.
nvd
CVE-2026-20445P4MEDIUMCVSS 4.4v14.0v15.0+1 more2026-03-02
CVE-2026-20445 [MEDIUM] CWE-367 CVE-2026-20445: In MDDP, there is a possible system crash due to a race condition. This could lead to local denial o
In MDDP, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10289875; Issue ID: MSV-5184.
nvd
CVE-2024-20020P4MEDIUMCVSS 4.4v13.02024-03-04
CVE-2024-20020 [MEDIUM] CWE-787 CVE-2024-20020: In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead
In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08522504; Issue ID: ALPS08522504.
nvd
CVE-2021-0541P4MEDIUMCVSS 4.4v11.0vAndroid-112021-06-22
CVE-2021-0541 [MEDIUM] CWE-125 CVE-2021-0541: In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds rea
In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258455
nvd
CVE-2023-21212P4MEDIUMCVSS 4.4v13.0vAndroid-132023-06-28
CVE-2023-21212 [MEDIUM] CWE-125 CVE-2023-21212: In multiple files, there is a possible out of bounds read due to a missing bounds check. This could
In multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262236031
nvd
CVE-2021-0677P4MEDIUMCVSS 4.4v11.02021-12-17
CVE-2021-0677 [MEDIUM] CWE-190 CVE-2021-0677: In ccu driver, there is a possible out of bounds read due to an integer overflow. This could lead to
In ccu driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05827154; Issue ID: ALPS05827154.
nvd
CVE-2023-32852P4MEDIUMCVSS 4.4v11.0v12.0+1 more2023-12-04
CVE-2023-32852 [MEDIUM] CVE-2023-32852: In cameraisp, there is a possible information disclosure due to improper input validation. This coul
In cameraisp, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07670971; Issue ID: ALPS07670971.
nvd
CVE-2024-20030P4MEDIUMCVSS 4.4v12.0v13.0+1 more2024-03-04
CVE-2024-20030 [MEDIUM] CVE-2024-20030: In da, there is a possible information disclosure due to improper input validation. This could lead
In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541741.
nvd
CVE-2021-25500P4MEDIUMCVSS 4.4v10.0v11.02021-11-05
CVE-2021-25500 [MEDIUM] CWE-20 CVE-2021-25500: A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrit
A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.
nvd