cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 31 of 339
CVE-2026-0098P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2026-0098 [HIGH] CWE-441 CVE-2026-0098: In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictio In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0091P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2026-0091 [HIGH] CWE-269 CVE-2026-0091: In multiple locations, there is a possible way to execute code in the launcher process due to an ove In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-13839P3CRITICALCVSS 9.8v7.2v8.0+3 more2020-06-05
CVE-2020-13839 [CRITICAL] CWE-120 CVE-2020-13839: An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets) An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via a custom AT command handler buffer overflow. The LG ID is LVE-SMP-200007 (June 2020).
nvd
CVE-2020-10850P3CRITICALCVSS 9.8v8.0v8.1+2 more2020-03-24
CVE-2020-10850 [CRITICAL] CWE-120 CVE-2020-10850: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The secure bootloade has a buffer overflow of the USB buffer, leading to arbitrary code execution. The Samsung ID is SVE-2019-15872 (January 2020).
nvd
CVE-2019-20611P3CRITICALCVSS 9.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20611 [CRITICAL] CWE-787 CVE-2019-20611: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), Go(8.1), P(9.0), and Go(9.0) An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), Go(8.1), P(9.0), and Go(9.0) (Exynos chipsets) software. A baseband stack overflow leads to arbitrary code execution. The Samsung ID is SVE-2019-13963 (April 2019).
nvd
CVE-2020-10837P3CRITICALCVSS 9.8v9.0v10.02020-03-24
CVE-2020-10837 [CRITICAL] CWE-20 CVE-2020-10837: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. T An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet allows a stack overflow and arbitrary code execution. The Samsung ID is SVE-2019-15984 (February 2020).
nvd
CVE-2018-21051P3CRITICALCVSS 9.8v7.0v7.1.0+4 more2020-04-08
CVE-2018-21051 [CRITICAL] CWE-74 CVE-2018-21051: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is an invalid free in the fingerprint Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2018-12853 (October 2018).
nvd
CVE-2018-21089P3CRITICALCVSS 9.8v7.0v7.1.0+2 more2020-04-08
CVE-2018-21089 [CRITICAL] CWE-190 CVE-2018-21089: An issue was discovered on Samsung mobile devices with N(7.x) (MT6755/MT6757 Mediatek models) softwa An issue was discovered on Samsung mobile devices with N(7.x) (MT6755/MT6757 Mediatek models) software. Bootloader has an integer overflow that leads to arbitrary code execution via the download offset control. The Samsung ID is SVE-2017-10732 (January 2018).
nvd
CVE-2018-21052P3CRITICALCVSS 9.8v7.0v7.1.0+4 more2020-04-08
CVE-2018-21052 [CRITICAL] CWE-119 CVE-2018-21052: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.X) (Exynos chipsets) software. An issue was discovered on Samsung mobile devices with N(7.x) and O(8.X) (Exynos chipsets) software. There is incorrect usage of shared memory in the vaultkeeper Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2018-12855 (October 2018).
nvd
CVE-2020-11603P3CRITICALCVSS 9.8v9.0v10.02020-04-08
CVE-2020-11603 [CRITICAL] CWE-843 CVE-2020-11603: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) so An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) software. Type confusion in the MLDAP Trustlet allows arbitrary code execution. The Samsung ID is SVE-2020-16599 (April 2020).
nvd
CVE-2020-25279P3CRITICALCVSS 9.8v8.0v8.1+2 more2020-09-11
CVE-2020-25279 [CRITICAL] CWE-120 CVE-2020-25279: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The baseband component has a buffer overflow via an abnormal SETUP message, leading to execution of arbitrary code. The Samsung ID is SVE-2020-18098 (September 2020).
nvd
CVE-2020-13840P3CRITICALCVSS 9.8v7.2v8.0+3 more2020-06-05
CVE-2020-13840 [CRITICAL] CWE-120 CVE-2020-13840: An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets) An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via an MTK AT command handler buffer overflow. The LG ID is LVE-SMP-200008 (June 2020).
nvd
CVE-2025-71252P3HIGHCVSS 7.5v13.0v14.0+2 more2026-05-06
CVE-2025-71252 [HIGH] CWE-20 CVE-2025-71252: In Modem IMS, there is a possible improper input validation. This could lead to remote denial of ser In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
CVE-2025-71254P3HIGHCVSS 7.5v13.0v14.0+2 more2026-05-06
CVE-2025-71254 [HIGH] CWE-20 CVE-2025-71254: In Modem IMS, there is a possible improper input validation. This could lead to remote denial of ser In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
CVE-2025-71253P3HIGHCVSS 7.5v13.0v14.0+2 more2026-05-06
CVE-2025-71253 [HIGH] CWE-20 CVE-2025-71253: In Modem IMS, there is a possible improper input validation. This could lead to remote denial of ser In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
CVE-2025-71255P3HIGHCVSS 7.5v13.0v14.0+2 more2026-05-06
CVE-2025-71255 [HIGH] CWE-20 CVE-2025-71255: In Modem IMS, there is a possible improper input validation. This could lead to remote denial of ser In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
CVE-2018-21057P3CRITICALCVSS 9.8v7.0v7.1.0+5 more2020-04-08
CVE-2018-21057 [CRITICAL] CWE-787 CVE-2018-21057: An issue was discovered on Samsung mobile devices with N(7.x) O(8.x, and P(9.0) (Exynos chipsets) so An issue was discovered on Samsung mobile devices with N(7.x) O(8.x, and P(9.0) (Exynos chipsets) software. There is a stack-based buffer overflow in the Shannon Baseband. The Samsung ID is SVE-2018-12757 (September 2018).
nvd
CVE-2025-71256P3HIGHCVSS 7.5v13.0v14.0+2 more2026-05-06
CVE-2025-71256 [HIGH] CWE-20 CVE-2025-71256: In nr modem, there is a possible improper input validation. This could lead to remote denial of serv In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
CVE-2022-26093P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-04-11
CVE-2022-26093 [CRITICAL] CWE-476 CVE-2022-26093: Null pointer dereference vulnerability in parser_irot function in libsimba library prior to SMR Apr- Null pointer dereference vulnerability in parser_irot function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
nvd
CVE-2022-26096P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-04-11
CVE-2022-26096 [CRITICAL] CWE-476 CVE-2022-26096: Null pointer dereference vulnerability in parser_ispe function in libsimba library prior to SMR Apr- Null pointer dereference vulnerability in parser_ispe function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
nvd
Google Android vulnerabilities | cvebase