Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 32 of 339
CVE-2022-27567P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-04-11
CVE-2022-27567 [CRITICAL] CWE-476 CVE-2022-27567: Null pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-
Null pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attackers.
nvd
CVE-2022-26095P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-04-11
CVE-2022-26095 [CRITICAL] CWE-476 CVE-2022-26095: Null pointer dereference vulnerability in parser_colr function in libsimba library prior to SMR Apr-
Null pointer dereference vulnerability in parser_colr function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
nvd
CVE-2022-26094P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-04-11
CVE-2022-26094 [CRITICAL] CWE-476 CVE-2022-26094: Null pointer dereference vulnerability in parser_auxC function in libsimba library prior to SMR Apr-
Null pointer dereference vulnerability in parser_auxC function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
nvd
CVE-2022-26097P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-04-11
CVE-2022-26097 [CRITICAL] CWE-476 CVE-2022-26097: Null pointer dereference vulnerability in parser_unknown_property function in libsimba library prior
Null pointer dereference vulnerability in parser_unknown_property function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
nvd
CVE-2026-0156P3HIGHCVSS 7.5vAndroid kernel2026-06-16
CVE-2026-0156 [HIGH] CWE-476 CVE-2026-0156: In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missi
In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2017-18655P3CRITICALCVSS 9.8v6.0v7.0+3 more2020-04-07
CVE-2017-18655 [CRITICAL] CWE-787 CVE-2017-18655: An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a stack-
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a stack-based buffer overflow with resultant memory corruption in a trustlet. The Samsung IDs are SVE-2017-8889, SVE-2017-8891, and SVE-2017-8892 (August 2017).
nvd
CVE-2022-33719P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-08-05
CVE-2022-33719 [CRITICAL] CWE-20 CVE-2022-33719: Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause inte
Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.
nvd
CVE-2025-36911P3HIGHCVSS 7.1vAndroid kernel2026-01-15
CVE-2025-36911 [HIGH] CVE-2025-36911: In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to re
In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-20416P3HIGHCVSS 7.2v15.0v16.02026-03-02
CVE-2026-20416 [HIGH] CWE-787 CVE-2026-20416: In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315038 / ALPS10340155; Issue ID: MSV-5155.
nvd
CVE-2012-6301P4MEDIUMCVSS 5.0PoCv4.0.32012-12-10
CVE-2012-6301 [MEDIUM] CWE-20 CVE-2012-6301: The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (appli
The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted market: URI in the SRC attribute of an IFRAME element.
nvd
CVE-2020-0416P3HIGHCVSS 8.8v8.0v8.1+4 more2020-10-14
CVE-2020-0416 [HIGH] CWE-1188 CVE-2020-0416: In multiple settings screens, there are possible tapjacking attacks due to an insecure default value
In multiple settings screens, there are possible tapjacking attacks due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1Android ID: A-
nvd
CVE-2019-2028P3HIGHCVSS 8.8v7.0v7.1.1+4 more2019-04-19
CVE-2019-2028 [HIGH] CWE-20 CVE-2019-2028: In numerous hand-crafted functions in libmpeg2, NEON registers are not preserved. This could lead to
In numerous hand-crafted functions in libmpeg2, NEON registers are not preserved. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-120644655.
nvd
CVE-2020-0198P3HIGHCVSS 7.5v10.0vAndroid-102020-06-11
CVE-2020-0198 [HIGH] CWE-190 CVE-2020-0198: In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer ove
In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146428941
nvd
CVE-2022-30712P3CRITICALCVSS 9.1v10.0v11.0+1 more2022-06-07
CVE-2022-30712 [CRITICAL] CWE-20 CVE-2022-30712: Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to
Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.
nvd
CVE-2019-2014P3HIGHCVSS 8.8v7.0v7.1.1+5 more2019-06-19
CVE-2019-2014 [HIGH] CWE-787 CVE-2019-2014: In rw_t3t_handle_get_sc_poll_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missi
In rw_t3t_handle_get_sc_poll_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android
nvd
CVE-2019-2015P3HIGHCVSS 8.8v7.0v7.1.1+5 more2019-06-19
CVE-2019-2015 [HIGH] CWE-787 CVE-2019-2015: In rw_t3t_act_handle_check_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing
In rw_t3t_act_handle_check_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9
nvd
CVE-2019-2012P3HIGHCVSS 8.8v7.0v7.1.1+5 more2019-06-19
CVE-2019-2012 [HIGH] CWE-787 CVE-2019-2012: In rw_t3t_act_handle_fmt_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing b
In rw_t3t_act_handle_fmt_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9An
nvd
CVE-2019-2013P3HIGHCVSS 8.8v7.0v7.1.1+5 more2019-06-19
CVE-2019-2013 [HIGH] CWE-787 CVE-2019-2013: In rw_t3t_act_handle_sro_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing b
In rw_t3t_act_handle_sro_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9An
nvd
CVE-2016-2433P3HIGHCVSS 8.8≤ 6.0.12017-04-21
CVE-2016-2433 [HIGH] CWE-284 CVE-2016-2433: The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows
The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to execute arbitrary code in the context of the kernel.
nvd
CVE-2019-2105P3HIGHCVSS 8.8v7.0v7.1.1+5 more2019-07-08
CVE-2019-2105 [HIGH] CWE-908 CVE-2019-2105: In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to unini
In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0
nvd