cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 338 of 339
CVE-2022-20261P4LOWCVSS 2.3v13.0vAndroid-132022-08-12
CVE-2022-20261 [LOW] CWE-862 CVE-2022-20261: In LocationManager, there is a possible way to get location information due to a missing permission In LocationManager, there is a possible way to get location information due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-219835125
nvd
CVE-2020-11606P4LOWCVSS 2.4v10.02020-04-08
CVE-2020-11606 [LOW] CVE-2020-11606: An issue was discovered on Samsung mobile devices with Q(10.0) software. Information about applicati An issue was discovered on Samsung mobile devices with Q(10.0) software. Information about application preview (in the Secure Folder) leaks on a locked device. The Samsung ID is SVE-2019-16463 (April 2020).
nvd
CVE-2011-2343P4LOWCVSS 2.4fixed in 2.3.6v2.32020-02-12
CVE-2011-2343 [LOW] CWE-200 CVE-2011-2343: The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact The Bluetooth stack in Android before 2.3.6 allows a physically proximate attacker to obtain contact information via an AT phonebook transfer.
nvd
CVE-2020-11602P4LOWCVSS 2.4v9.0v10.02020-04-08
CVE-2020-11602 [LOW] CVE-2020-11602: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Google Assistant An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Google Assistant leaks clipboard contents on a locked device. The Samsung ID is SVE-2019-16558 (April 2020).
nvd
CVE-2018-21073P4LOWCVSS 2.4v7.0v7.1.0+3 more2020-04-08
CVE-2018-21073 [LOW] CWE-200 CVE-2018-21073: An issue was discovered on Samsung mobile devices with N(7.x) and O(8.0) (Galaxy S9+, Galaxy S9, Gal An issue was discovered on Samsung mobile devices with N(7.x) and O(8.0) (Galaxy S9+, Galaxy S9, Galaxy S8+, Galaxy S8, Note 8). There is access to Clipboard content in the locked state via the Edge panel. The Samsung ID is SVE-2017-10748 (May 2018).
nvd
CVE-2016-11027P4LOWCVSS 2.4v6.02020-04-07
CVE-2016-11027 [LOW] CWE-200 CVE-2016-11027: An issue was discovered on Samsung mobile devices with M(6.0) software. In the Shade Locked state, a An issue was discovered on Samsung mobile devices with M(6.0) software. In the Shade Locked state, a physically proximate attacker can read notifications on the lock screen. The Samsung ID is SVE-2016-7132 (December 2016).
nvd
CVE-2020-10830P4LOWCVSS 2.4v9.0v10.02020-03-24
CVE-2020-10830 [LOW] CVE-2020-10830: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can vi An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can view notifications by entering many PINs in Lockdown mode. The Samsung ID is SVE-2019-16590 (March 2020).
nvd
CVE-2019-20534P4LOWCVSS 2.4v9.02020-03-24
CVE-2019-20534 [LOW] CVE-2019-20534: An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can view home-scre An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can view home-screen wallpaper by adjusting the brightness of a locked screen. The Samsung ID is SVE-2019-15540 (December 2019).
nvd
CVE-2019-20579P4LOWCVSS 2.4v7.0v7.1.0+5 more2020-03-24
CVE-2019-20579 [LOW] CWE-306 CVE-2019-20579: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Gallery An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Gallery allows attackers to enable Location information sharing from the lock screen. The Samsung ID is SVE-2019-14462 (August 2019).
nvd
CVE-2019-20598P4LOWCVSS 2.4v8.0v8.12020-03-24
CVE-2019-20598 [LOW] CWE-306 CVE-2019-20598: An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's l An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's learned words, and the clipboard contents, via the lock screen. The Samsung IDs are SVE-2018-12896, SVE-2018-12897 (May 2019).
nvd
CVE-2017-18673P4LOWCVSS 2.4v7.0v7.1.0+2 more2020-04-07
CVE-2017-18673 [LOW] CWE-20 CVE-2017-18673: An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can disable the An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can disable the Location service on a locked device, making it impossible for the rightful owner to find a stolen device. The Samsung ID is SVE-2017-8524 (May 2017).
nvd
CVE-2022-20245P4LOWCVSS 2.4v13.0.0vAndroid-132022-08-11
CVE-2022-20245 [LOW] CVE-2022-20245: In WindowManager, there is a possible method to create a recording of the lock screen due to an inse In WindowManager, there is a possible method to create a recording of the lock screen due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-215005011
nvd
CVE-2026-0092CRITICALCVSS 10.0v172026-06-17
CVE-2026-0092 [CRITICAL] CVE-2026-0092: In Package Manager, there is a possible device lock controller bypass due to a missing permission check In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2026-0082CRITICALCVSS 10.0v172026-06-17
CVE-2026-0082 [CRITICAL] CVE-2026-0082: In tryStartActivity of NfcDispatcher In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2026-0071CRITICALCVSS 10.0v172026-06-17
CVE-2026-0071 [CRITICAL] CVE-2026-0071: In SettingsLib, there is a possible missing permission check due to a logic error in the code In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2026-0063CRITICALCVSS 10.0v172026-06-17
CVE-2026-0063 [CRITICAL] CVE-2026-0063: In setAllowedCarriers of PhoneInterfaceManager In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2026-0081CRITICALCVSS 10.0v172026-06-17
CVE-2026-0081 [CRITICAL] CVE-2026-0081: In NFC, there is a possible way to spoof an NFC event due to a missing permission check In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2026-28575CRITICALCVSS 10.0v172026-06-17
CVE-2026-28575 [CRITICAL] CVE-2026-28575: In PackageInstaller In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2026-0068CRITICALCVSS 10.0v172026-06-17
CVE-2026-0068 [CRITICAL] CVE-2026-0068: In createSessionInternal of PackageInstallerService In createSessionInternal of PackageInstallerService.java, there is a possible method to remove a DPC app from a managed device without DO consent due to desync from persistence. This could lead to local escalation of privilege if a user can install a malicious app with no additional execution privileges needed. User interaction is needed for exploitation.
cvelistv5
CVE-2026-28615CRITICALCVSS 10.0v172026-06-17
CVE-2026-28615 [CRITICAL] CVE-2026-28615: In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
Google Android vulnerabilities | cvebase