Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 332 of 339
CVE-2021-0994P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-0994 [LOW] CWE-862 CVE-2021-0994: In requestRouteToHostAddress of ConnectivityService.java, there is a possible way to determine wheth
In requestRouteToHostAddress of ConnectivityService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:
nvd
CVE-2021-0982P4LOWCVSS 3.3v12.0vAndroid-122021-12-15
CVE-2021-0982 [LOW] CWE-862 CVE-2021-0982: In getOrganizationNameForUser of DevicePolicyManagerService.java, there is a possible organization n
In getOrganizationNameForUser of DevicePolicyManagerService.java, there is a possible organization name disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-192368508
nvd
CVE-2022-36852P4LOWCVSS 3.3v11.0v12.02022-09-09
CVE-2022-36852 [LOW] CWE-285 CVE-2022-36852: Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local at
Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.
nvd
CVE-2022-22266P4LOWCVSS 3.3v9.0v10.0+1 more2022-01-10
CVE-2022-22266 [LOW] CWE-269 CVE-2022-22266: (Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity applicati
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.
nvd
CVE-2022-22269P4LOWCVSS 3.3v9.0v10.0+1 more2022-01-10
CVE-2022-22269 [LOW] CWE-285 CVE-2022-22269: Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allo
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.
nvd
CVE-2021-25472P4LOWCVSS 3.3v8.1v9.0+2 more2021-10-06
CVE-2021-25472 [LOW] CWE-264 CVE-2021-25472: An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release
An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.
nvd
CVE-2022-33692P4LOWCVSS 3.3v11.0v12.02022-07-12
CVE-2022-33692 [LOW] CWE-213 CVE-2022-33692: Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows lo
Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.
nvd
CVE-2022-33687P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-33687 [LOW] CWE-200 CVE-2022-33687: Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows loc
Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.
nvd
CVE-2022-33696P4LOWCVSS 3.3v12.02022-07-12
CVE-2022-33696 [LOW] CWE-213 CVE-2022-33696: Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local
Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.
nvd
CVE-2021-25457P4LOWCVSS 3.3v10.0v11.02021-09-09
CVE-2021-25457 [LOW] CWE-20 CVE-2021-25457: An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows loca
An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.
nvd
CVE-2021-25486P4LOWCVSS 3.3v8.1v9.0+2 more2021-10-06
CVE-2021-25486 [LOW] CWE-200 CVE-2021-25486: Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker
Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing packet in log.
nvd
CVE-2022-20340P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20340 [LOW] CWE-862 CVE-2022-20340: In SELinux policy, there is a possible way of inferring which websites are being opened in the brows
In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-166269532
nvd
CVE-2022-20339P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20339 [LOW] CVE-2022-20339: In Android, there is a possible access of network neighbor table information due to an insecure SEpo
In Android, there is a possible access of network neighbor table information due to an insecure SEpolicy configuration. This could lead to local information disclosure of network topography with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-171572148
nvd
CVE-2022-20342P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20342 [LOW] CWE-1188 CVE-2022-20342: In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default
In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-143534321
nvd
CVE-2022-33729P4LOWCVSS 3.3v10.0v11.0+1 more2022-08-05
CVE-2022-33729 [LOW] CWE-20 CVE-2022-33729: Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 R
Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.
nvd
CVE-2022-33689P4LOWCVSS 3.3v10.0v11.0+1 more2022-07-12
CVE-2022-33689 [LOW] CWE-287 CVE-2022-33689: Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attacker
Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.
nvd
CVE-2021-25501P4LOWCVSS 3.3v10.0v11.02021-11-05
CVE-2021-25501 [LOW] CWE-284 CVE-2021-25501: An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR N
An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.
nvd
CVE-2022-20328P4LOWCVSS 3.3v13.0vAndroid-132022-08-12
CVE-2022-20328 [LOW] CWE-862 CVE-2022-20328: In PackageManager, there is a possible way to determine whether an app is installed due to a missing
In PackageManager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-184948501
nvd
CVE-2022-33728P4LOWCVSS 3.3v10.0v11.0+1 more2022-08-05
CVE-2022-33728 [LOW] CWE-200 CVE-2022-33728: Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attacker
Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via Settings.Gloabal.
nvd
CVE-2022-20241P4LOWCVSS 3.3v13.0.0vAndroid-132022-08-11
CVE-2022-20241 [LOW] CWE-20 CVE-2022-20241: In Messaging, there is a possible way to attach a private file to an SMS message due to improper inp
In Messaging, there is a possible way to attach a private file to an SMS message due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-217185011
nvd