cbcvebase.

Google Android vulnerabilities

6,771 known vulnerabilities affecting google/android.

Total CVEs
6,771
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL472HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 339 of 339
CVE-2026-0064CRITICALCVSS 10.0v172026-06-17
CVE-2026-0064 [CRITICAL] CVE-2026-0064: In multiple places, there is a possible persistent denial of service due to resource exhaustion In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2026-0083CRITICALCVSS 10.0v172026-06-17
CVE-2026-0083 [CRITICAL] CVE-2026-0083: In Nfc::eventCallback() of Nfc In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2026-28587CRITICALCVSS 10.0v172026-06-17
CVE-2026-28587 [CRITICAL] CVE-2026-28587: In MmsSmsProvider of MmsSmsProvider In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2018-21077P4LOWCVSS 2.4v6.0v7.0+4 more2020-04-08
CVE-2018-21077 [LOW] CWE-200 CVE-2018-21077: An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is a Clipboard content disclosure in the locked state because the keyboard may be used during an emergency call. The Samsung ID is SVE-2017-11107 (April 2018).
nvd
CVE-2019-20559P4LOWCVSS 2.4v9.02020-03-24
CVE-2019-20559 [LOW] CWE-306 CVE-2019-20559: An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery allows viewing of ph An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery allows viewing of photos on the lock screen. The Samsung ID is SVE-2019-15055 (October 2019).
nvd
CVE-2025-48640HIGHCVSS 8.0v172026-06-17
CVE-2025-48640 [HIGH] CVE-2025-48640: In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2025-48643HIGHCVSS 7.8v172026-06-17
CVE-2025-48643 [HIGH] CVE-2025-48643: In multiple locations there is a possible provisioning bypass due to improper input validation In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2026-0019HIGHCVSS 7.8v172026-06-17
CVE-2026-0019 [HIGH] CVE-2026-0019: In SettingsLib, there is a possible way to disable system components due to a logic error in the code In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2025-48617HIGHCVSS 7.8v172026-06-17
CVE-2025-48617 [HIGH] CVE-2025-48617: In overrideConfig of CarrierConfigLoader In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
CVE-2025-48571MEDIUMCVSS 4.3v172026-06-17
CVE-2025-48571 [MEDIUM] CVE-2025-48571: In multiple functions of btm_sec In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
cvelistv5
CVE-2026-0057LOWCVSS 3.3v172026-06-17
CVE-2026-0057 [LOW] CVE-2026-0057: In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
cvelistv5
← Previous339 / 339
Google Android vulnerabilities | cvebase