Google Android vulnerabilities
6,771 known vulnerabilities affecting google/android.
Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 339 of 339
CVE-2026-0064CRITICALCVSS 10.0v172026-06-17
CVE-2026-0064 [CRITICAL] CVE-2026-0064: In multiple places, there is a possible persistent denial of service due to resource exhaustion
In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2026-0083CRITICALCVSS 10.0v172026-06-17
CVE-2026-0083 [CRITICAL] CVE-2026-0083: In Nfc::eventCallback() of Nfc
In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2026-28587CRITICALCVSS 10.0v172026-06-17
CVE-2026-28587 [CRITICAL] CVE-2026-28587: In MmsSmsProvider of MmsSmsProvider
In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2018-21077P4LOWCVSS 2.4v6.0v7.0+4 more2020-04-08
CVE-2018-21077 [LOW] CWE-200 CVE-2018-21077: An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is a Clipboard content disclosure in the locked state because the keyboard may be used during an emergency call. The Samsung ID is SVE-2017-11107 (April 2018).
nvd
CVE-2019-20559P4LOWCVSS 2.4v9.02020-03-24
CVE-2019-20559 [LOW] CWE-306 CVE-2019-20559: An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery allows viewing of ph
An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery allows viewing of photos on the lock screen. The Samsung ID is SVE-2019-15055 (October 2019).
nvd
CVE-2025-48640HIGHCVSS 8.0v172026-06-17
CVE-2025-48640 [HIGH] CVE-2025-48640: In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check
In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2025-48643HIGHCVSS 7.8v172026-06-17
CVE-2025-48643 [HIGH] CVE-2025-48643: In multiple locations there is a possible provisioning bypass due to improper input validation
In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2026-0019HIGHCVSS 7.8v172026-06-17
CVE-2026-0019 [HIGH] CVE-2026-0019: In SettingsLib, there is a possible way to disable system components due to a logic error in the code
In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2025-48617HIGHCVSS 7.8v172026-06-17
CVE-2025-48617 [HIGH] CVE-2025-48617: In overrideConfig of CarrierConfigLoader
In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2025-48571MEDIUMCVSS 4.3v172026-06-17
CVE-2025-48571 [MEDIUM] CVE-2025-48571: In multiple functions of btm_sec
In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
cvelistv5
CVE-2026-0057LOWCVSS 3.3v172026-06-17
CVE-2026-0057 [LOW] CVE-2026-0057: In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check
In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
← Previous339 / 339