Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 328 of 339
CVE-2024-0052P4LOWCVSS 3.3v14.0v142024-03-11
CVE-2024-0052 [LOW] CWE-862 CVE-2024-0052: In multiple functions of healthconnect, there is a possible leakage of exercise route data due to a
In multiple functions of healthconnect, there is a possible leakage of exercise route data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-25991P4LOWCVSS 3.3v13.0v132024-03-11
CVE-2024-25991 [LOW] CWE-125 CVE-2024-25991: In acpm_tmu_ipc_handler of tmu_plugin.c, there is a possible out of bounds read due to a missing bou
In acpm_tmu_ipc_handler of tmu_plugin.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20257P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20257 [LOW] CVE-2022-20257: In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to
In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222289114
nvd
CVE-2023-40137P4LOWCVSS 3.3v11.0v12.0+6 more2023-10-27
CVE-2023-40137 [LOW] CVE-2023-40137: In multiple functions of DialogFillUi.java, there is a possible way to view another user's images du
In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40138P4LOWCVSS 3.3v11.0v12.0+6 more2023-10-27
CVE-2023-40138 [LOW] CVE-2023-40138: In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused de
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-33726P4LOWCVSS 3.3v10.0v11.0+1 more2022-08-05
CVE-2022-33726 [LOW] CWE-561 CVE-2022-33726: Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attack
Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity.
nvd
CVE-2023-40135P4LOWCVSS 3.3v11.0v12.0+6 more2023-10-27
CVE-2023-40135 [LOW] CVE-2023-40135: In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due
In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40136P4LOWCVSS 3.3v11.0v12.0+6 more2023-10-27
CVE-2023-40136 [LOW] CVE-2023-40136: In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a co
In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40134P4LOWCVSS 3.3v12.0v12.1+4 more2023-10-27
CVE-2023-40134 [LOW] CVE-2023-40134: In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confu
In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20267P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20267 [LOW] CWE-862 CVE-2022-20267: In bluetooth, there is a possible way to enable or disable bluetooth connection without user consent
In bluetooth, there is a possible way to enable or disable bluetooth connection without user consent due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-211646835
nvd
CVE-2022-20335P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20335 [LOW] CWE-862 CVE-2022-20335: In Wifi Slice, there is a possible way to adjust Wi-Fi settings even when the permission has been di
In Wifi Slice, there is a possible way to adjust Wi-Fi settings even when the permission has been disabled due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-178014725
nvd
CVE-2023-20726P4LOWCVSS 3.3v11.0v12.0+1 more2023-05-15
CVE-2023-20726 [LOW] CWE-862 CVE-2023-20726: In mnld, there is a possible leak of GPS location due to a missing permission check. This could lead
In mnld, there is a possible leak of GPS location due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07735968 / ALPS07884552 (For MT6880, MT6890, MT6980, MT6980D and MT6990 only); Issue ID: ALPS07735968 / ALPS07
nvd
CVE-2025-48616P4LOWCVSS 3.3v14.0v15.0+8 more2026-06-01
CVE-2025-48616 [LOW] CVE-2025-48616: In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode
In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0050P4LOWCVSS 3.3v15.0v16.0+6 more2026-06-01
CVE-2026-0050 [LOW] CWE-269 CVE-2026-0050: In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosu
In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0016P4LOWCVSS 3.3v16.0v16.0-qpr2_beta_1+4 more2026-06-01
CVE-2026-0016 [LOW] CWE-269 CVE-2026-0016: In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to ov
In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-28586P4LOWCVSS 3.3v14.0v15.0+8 more2026-06-01
CVE-2026-28586 [LOW] CWE-269 CVE-2026-28586: In multiple functions of AppOpsService.java, there is a possible missing permission check due to a p
In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0121P4LOWCVSS 2.9vAndroid kernel2026-03-10
CVE-2026-0121 [LOW] CWE-362 CVE-2026-0121: In VPU, there is a possible use-after-free read due to a race condition. This could lead to local in
In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20643P4LOWCVSS 3.9v12.0v13.0+2 more2025-02-03
CVE-2025-20643 [LOW] CWE-1295 CVE-2025-20643: In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to loca
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2056.
nvd
CVE-2021-25336P4LOWCVSS 3.3v9.0v10.02021-03-04
CVE-2021-25336 [LOW] CWE-269 CVE-2021-25336: Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-202
Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to acquire notification access via sending a crafted malicious intent.
nvd
CVE-2021-25451P4LOWCVSS 3.3v9.0v10.0+1 more2021-09-09
CVE-2021-25451 [LOW] CWE-287 CVE-2021-25451: A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows atta
A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.
nvd