Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 330 of 339
CVE-2022-30752P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-30752 [LOW] CWE-284 CVE-2022-30752: Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to S
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action.
nvd
CVE-2022-30751P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-30751 [LOW] CWE-284 CVE-2022-30751: Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to S
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action.
nvd
CVE-2022-30750P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-30750 [LOW] CWE-284 CVE-2022-30750: Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient p
Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected.
nvd
CVE-2022-33722P4LOWCVSS 3.3v12.02022-08-05
CVE-2022-33722 [LOW] CWE-285 CVE-2022-33722: Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacke
Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC address.
nvd
CVE-2022-33714P4LOWCVSS 3.3v10.0v11.0+1 more2022-08-05
CVE-2022-33714 [LOW] CWE-284 CVE-2022-33714: Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1
Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.
nvd
CVE-2022-36856P4LOWCVSS 3.3v12.02022-09-09
CVE-2022-36856 [LOW] CWE-284 CVE-2022-36856: Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows
Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via undefined permission.
nvd
CVE-2023-21232P4LOWCVSS 3.3v11.0v13.0+2 more2023-08-14
CVE-2023-21232 [LOW] CVE-2023-21232: In multiple locations, there is a possible way to retrieve sensor data without permissions due to a
In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-0076P4LOWCVSS 3.3v13.0v14.0+4 more2025-09-04
CVE-2025-0076 [LOW] CWE-862 CVE-2025-0076: In multiple locations, there is a possible way to view icons belonging to another user due to a miss
In multiple locations, there is a possible way to view icons belonging to another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-39887P4LOWCVSS 3.3v10.0v11.0+1 more2022-11-09
CVE-2022-39887 [LOW] CWE-284 CVE-2022-39887: Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Rel
Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.
nvd
CVE-2025-26428P4LOWCVSS 3.2v13.0v14.0+4 more2025-09-04
CVE-2025-26428 [LOW] CWE-290 CVE-2025-26428: In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a log
In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-21262P4LOWCVSS 3.1v12.0v12.1+4 more2023-07-13
CVE-2023-21262 [LOW] CWE-362 CVE-2023-21262: In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the
In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy indicator due to a race condition. This could lead to false user expectations. User interaction is needed for exploitation.
nvd
CVE-2015-6644P4LOWCVSS 3.3v4.4.4v5.0+6 more2016-01-06
CVE-2015-6644 [LOW] CWE-200 CVE-2015-6644: Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain se
Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.
nvd
CVE-2020-13837P4LOWCVSS 3.5v10.02020-06-04
CVE-2020-13837 [LOW] CWE-306 CVE-2020-13837: An issue was discovered on Samsung mobile devices with Q(10.0) software. The Lockscreen feature does
An issue was discovered on Samsung mobile devices with Q(10.0) software. The Lockscreen feature does not block Quick Panel access to Music Share. The Samsung ID is SVE-2020-17145 (June 2020).
nvd
CVE-2020-13838P4LOWCVSS 3.5v9.0v10.02020-06-04
CVE-2020-13838 [LOW] CWE-306 CVE-2020-13838: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscre
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscreen feature does not block access to Quick Panel and notifications. The Samsung ID is SVE-2020-17187 (June 2020).
nvd
CVE-2014-6060P4LOWCVSS 3.3≤ 4.4.32014-09-04
CVE-2014-6060 [LOW] CWE-399 CVE-2014-6060: The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause
The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.
nvd
CVE-2024-20038P4LOWCVSS 3.4v12.0v13.0+1 more2024-03-04
CVE-2024-20038 [LOW] CWE-125 CVE-2024-20038: In pq, there is a possible out of bounds read due to an incorrect bounds check. This could lead to l
In pq, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08495932; Issue ID: ALPS08495932.
nvd
CVE-2016-6770P4LOWCVSS 3.3v4.0v4.0.1+24 more2017-01-12
CVE-2016-6770 [LOW] CWE-284 CVE-2016-6770: An elevation of privilege vulnerability in the Framework API could enable a local malicious applicat
An elevation of privilege vulnerability in the Framework API could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate because it is a local bypass of restrictions on a constrained process. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-30202228.
nvd
CVE-2022-20358P4LOWCVSS 3.3v10.0v11.0+3 more2022-08-10
CVE-2022-20358 [LOW] CWE-862 CVE-2022-20358: In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected conten
In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 An
nvd
CVE-2020-0412P4LOWCVSS 3.3v8.0v8.1+4 more2020-10-14
CVE-2020-0412 [LOW] CWE-862 CVE-2020-0412: In setProcessMemoryTrimLevel of ActivityManagerService.java, there is a missing permission check. Th
In setProcessMemoryTrimLevel of ActivityManagerService.java, there is a missing permission check. This could lead to local information disclosure of foreground processes with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.0 Android-8.1 Android-9Android I
nvd
CVE-2020-0368P4LOWCVSS 3.3v11.0vAndroid-112020-12-15
CVE-2020-0368 [LOW] CWE-20 CVE-2020-0368: In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper inpu
In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper input validation. This could lead to local information disclosure of voicemail metadata with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-143230980
nvd