cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 306 of 339
CVE-2025-0077P4MEDIUMCVSS 4.0v15.0v152025-09-04
CVE-2025-0077 [MEDIUM] CWE-1223 CVE-2025-0077: In multiple functions of UserController.java, there is a possible lock screen bypass due to a race c In multiple functions of UserController.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0024P4MEDIUMCVSS 4.0v14.0v15.0+5 more2026-03-02
CVE-2026-0024 [MEDIUM] CWE-862 CVE-2026-0024: In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reve In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of media due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26425P4MEDIUMCVSS 4.0v14.0v15.0+2 more2025-09-04
CVE-2025-26425 [MEDIUM] CWE-266 CVE-2025-26425: In multiple functions of RoleService.java, there is a possible permission squatting vulnerability du In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This could lead to local escalation of privilege on versions of Android where android.permission.MANAGE_DEFAULT_APPLICATIONS was not defined with no additional execution privileges needed. User interaction is not needed
nvd
CVE-2025-48528P4MEDIUMCVSS 4.0v15.0v16.0+2 more2025-09-04
CVE-2025-48528 [MEDIUM] CWE-266 CVE-2025-48528: In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay att In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49731P4MEDIUMCVSS 4.0v13.0v132025-09-04
CVE-2024-49731 [MEDIUM] CWE-266 CVE-2024-49731: In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches wh In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new Pixel Watch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2026-0108P4MEDIUMCVSS 4.0vAndroid kernel2026-03-10
CVE-2026-0108 [MEDIUM] CWE-284 CVE-2026-0108: The register protection of the PowerVR GPU is incorrectly configured. This could lead to local infor The register protection of the PowerVR GPU is incorrectly configured. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-3839P4MEDIUMCVSS 5.5v4.0v4.0.1+20 more2016-08-05
CVE-2016-3839 [MEDIUM] CWE-284 CVE-2016-3839: Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-0 Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of Bluetooth 911 functionality) via a crafted application that sends a signal to a Bluetooth process, aka internal bug 28885210.
nvd
CVE-2016-6724P4MEDIUMCVSS 5.5≥ 4.0, < 4.4.4≥ 5.0, < 5.0.2+3 more2016-11-25
CVE-2016-6724 [MEDIUM] CWE-284 CVE-2016-6724: A denial of service vulnerability in the Input Manager Service in Android 4.x before 4.4.4, 5.0.x be A denial of service vulnerability in the Input Manager Service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to cause the device to continually reboot. This issue is rated as Moderate because it is a temporary denial of service that requi
nvd
CVE-2016-6763P4MEDIUMCVSS 5.5v4.0v4.0.1+24 more2017-01-12
CVE-2016-6763 [MEDIUM] CWE-284 CVE-2016-6763: A denial of service vulnerability in Telephony could enable a local malicious application to use a s A denial of service vulnerability in Telephony could enable a local malicious application to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of local permanent denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31530456.
nvd
CVE-2016-6690P4MEDIUMCVSS 5.5≤ 7.02016-10-10
CVE-2016-6690 [MEDIUM] CWE-284 CVE-2016-6690: The sound driver in the kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, The sound driver in the kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Nexus Player devices allows attackers to cause a denial of service (reboot) via a crafted application, aka internal bug 28838221.
nvd
CVE-2020-35548P4MEDIUMCVSS 5.5v10.02020-12-18
CVE-2020-35548 [MEDIUM] CVE-2020-35548: An issue was discovered in Finder on Samsung mobile devices with Q(10.0) software. A call to a non-e An issue was discovered in Finder on Samsung mobile devices with Q(10.0) software. A call to a non-existent provider allows attackers to cause a denial of service. The Samsung ID is SVE-2020-18629 (December 2020).
nvd
CVE-2021-25334P4MEDIUMCVSS 5.5v9.0v10.0+1 more2021-03-04
CVE-2021-25334 [MEDIUM] CWE-20 CVE-2021-25334: Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted application to cause permanent denial of service.
nvd
CVE-2022-36848P4MEDIUMCVSS 5.5v10.0v11.0+1 more2022-09-09
CVE-2022-36848 [MEDIUM] CWE-285 CVE-2022-36848: Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows l Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.
nvd
CVE-2015-3862P4MEDIUMCVSS 5.0≤ 5.12015-10-06
CVE-2015-3862 [MEDIUM] CVE-2015-3862: mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process cr mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22954006.
nvd
CVE-2016-6723P4MEDIUMCVSS 4.7≥ 4.0, < 4.4.4≥ 5.0, < 5.0.2+3 more2016-11-25
CVE-2016-6723 [MEDIUM] CWE-284 CVE-2016-6723: A denial of service vulnerability in Proxy Auto Config in Android 4.x before 4.4.4, 5.0.x before 5.0 A denial of service vulnerability in Proxy Auto Config in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuratio
nvd
CVE-2017-0497P4MEDIUMCVSS 4.7v7.0v7.1.0+1 more2017-03-08
CVE-2017-0497 [MEDIUM] CVE-2017-0497: A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuration. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33300701.
nvd
CVE-2017-0603P4MEDIUMCVSS 4.7v4.0v4.0.1+27 more2017-05-12
CVE-2017-0603 [MEDIUM] CWE-190 CVE-2017-0603: A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a A denial of service vulnerability in libstagefright in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuration. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35763994.
nvd
CVE-2016-6774P4MEDIUMCVSS 4.7≤ 7.02017-01-12
CVE-2016-6774 [MEDIUM] CWE-200 CVE-2016-6774: An information disclosure vulnerability in Package Manager could enable a local malicious applicatio An information disclosure vulnerability in Package Manager could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: 7.0. Android ID: A-31251489.
nvd
CVE-2015-3878P4MEDIUMCVSS 4.3v5.0v5.12015-10-06
CVE-2015-3878 [MEDIUM] CWE-264 CVE-2015-3878: Media Projection in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to by Media Projection in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to bypass an intended screen-recording warning feature and obtain sensitive screen-snapshot information via a crafted application that references a long application name, aka internal bug 23345192.
nvd
CVE-2016-6769P4MEDIUMCVSS 4.6v5.0v5.0.1+6 more2017-01-12
CVE-2016-6769 [MEDIUM] CWE-284 CVE-2016-6769: An elevation of privilege vulnerability in Smart Lock could enable a local malicious user to access An elevation of privilege vulnerability in Smart Lock could enable a local malicious user to access Smart Lock settings without a PIN. This issue is rated as Moderate because it first requires physical access to an unlocked device where Smart Lock was the last settings pane accessed by the user. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1. And
nvd
Google Android vulnerabilities | cvebase