Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 329 of 339
CVE-2023-40127P4LOWCVSS 3.3v11.0v12.0+6 more2023-10-27
CVE-2023-40127 [LOW] CVE-2023-40127: In multiple locations, there is a possible way to access screenshots due to a confused deputy. This
In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0422P4LOWCVSS 3.3v8.0v8.1+4 more2020-10-14
CVE-2020-0422 [LOW] CVE-2020-0422: In constructImportFailureNotification of NotificationImportExportListener.java, there is a possible
In constructImportFailureNotification of NotificationImportExportListener.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local information disclosure of contact data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Andr
nvd
CVE-2020-0459P4LOWCVSS 3.3v8.0v8.1+3 more2020-12-14
CVE-2020-0459 [LOW] CWE-862 CVE-2020-0459: In sendConfiguredNetworkChangedBroadcast of WifiConfigManager.java, there is a possible leak of sens
In sendConfiguredNetworkChangedBroadcast of WifiConfigManager.java, there is a possible leak of sensitive WiFi configuration data due to a missing permission check. This could lead to local information disclosure of WiFi network names with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:
nvd
CVE-2020-0047P4LOWCVSS 3.3v10.0vAndroid-102020-03-10
CVE-2020-0047 [LOW] CWE-862 CVE-2020-0047: In setMasterMute of AudioService.java, there is a missing permission check. This could lead to local
In setMasterMute of AudioService.java, there is a missing permission check. This could lead to local silencing of audio with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141622311
nvd
CVE-2022-20526P4LOWCVSS 3.3v13.0vAndroid-132022-12-16
CVE-2022-20526 [LOW] CWE-787 CVE-2022-20526: In CanvasContext::draw of CanvasContext.cpp, there is a possible out of bounds write due to a missin
In CanvasContext::draw of CanvasContext.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-229742774
nvd
CVE-2022-39898P4LOWCVSS 3.3v10.0v11.0+2 more2022-12-08
CVE-2022-39898 [LOW] CWE-284 CVE-2022-39898: Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attack
Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.
nvd
CVE-2022-39896P4LOWCVSS 3.3v10.0v11.0+1 more2022-12-08
CVE-2022-39896 [LOW] CWE-284 CVE-2022-39896: Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access
Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
nvd
CVE-2022-39849P4LOWCVSS 3.3v10.0v11.0+1 more2022-10-07
CVE-2022-39849 [LOW] CWE-284 CVE-2022-39849: Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows una
Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.
nvd
CVE-2022-39850P4LOWCVSS 3.3v10.0v11.0+1 more2022-10-07
CVE-2022-39850 [LOW] CWE-284 CVE-2022-39850: Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allow
Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.
nvd
CVE-2022-39894P4LOWCVSS 3.3v10.0v11.0+1 more2022-12-08
CVE-2022-39894 [LOW] CWE-284 CVE-2022-39894: Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-20
Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
nvd
CVE-2022-33725P4LOWCVSS 3.3v10.0v11.02022-08-05
CVE-2022-33725 [LOW] CWE-94 CVE-2022-33725: A vulnerability using PendingIntent in Knox VPN prior to SMR Aug-2022 Release 1 allows attackers to
A vulnerability using PendingIntent in Knox VPN prior to SMR Aug-2022 Release 1 allows attackers to access content providers with system privilege.
nvd
CVE-2022-39913P4LOWCVSS 3.3fixed in 13.02022-12-08
CVE-2022-39913 [LOW] CWE-200 CVE-2022-39913: Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13)
Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user profiles information.
nvd
CVE-2023-20932P4LOWCVSS 3.3v10.0v11.0+4 more2023-02-28
CVE-2023-20932 [LOW] CWE-20 CVE-2023-20932: In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging
In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts belonging to other users due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Andr
nvd
CVE-2021-38591P4LOWCVSS 3.3v9.0v10.02021-08-12
CVE-2021-38591 [LOW] CVE-2021-38591: An issue was discovered on LG mobile devices with Android OS P and Q software for mt6762/mt6765/mt68
An issue was discovered on LG mobile devices with Android OS P and Q software for mt6762/mt6765/mt6883. Attackers can change some of the NvRAM content by leveraging the misconfiguration of a debug command. The LG ID is LVE-SMP-210005 (August 2021).
nvd
CVE-2022-26090P4LOWCVSS 3.3v10.0v11.02022-04-11
CVE-2022-26090 [LOW] CWE-815 CVE-2022-26090: Improper access control vulnerability in SamsungContacts prior to SMR Apr-2022 Release 1 allows that
Improper access control vulnerability in SamsungContacts prior to SMR Apr-2022 Release 1 allows that attackers can access contact information without permission.
nvd
CVE-2022-22272P4LOWCVSS 3.3v10.0v11.0+1 more2022-01-10
CVE-2022-22272 [LOW] CWE-285 CVE-2022-22272: Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get I
Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission
nvd
CVE-2022-30757P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-30757 [LOW] CWE-285 CVE-2022-30757: Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CI
Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.
nvd
CVE-2023-33879P4LOWCVSS 3.3v10.0v11.0+2 more2023-07-12
CVE-2023-33879 [LOW] CWE-862 CVE-2023-33879: In music service, there is a missing permission check. This could lead to local information disclosu
In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2023-33880P4LOWCVSS 3.3v10.0v11.0+2 more2023-07-12
CVE-2023-33880 [LOW] CWE-862 CVE-2023-33880: In music service, there is a missing permission check. This could lead to local information disclosu
In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
nvd
CVE-2021-25515P4LOWCVSS 3.3v9.0v10.0+1 more2021-12-08
CVE-2021-25515 [LOW] CWE-269 CVE-2021-25515: An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows atta
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.
nvd