cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 34 of 339
CVE-2023-40140P3HIGHCVSS 7.8v11.0v12.0+6 more2023-10-27
CVE-2023-40140 [HIGH] CWE-416 CVE-2023-40140: In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execu In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48535P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48535 [HIGH] CWE-502 CVE-2025-48535: In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to expl In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a launch anywhere vulnerability due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34740P3HIGHCVSS 7.8v12.0v12.1+6 more2024-08-15
CVE-2024-34740 [HIGH] CWE-190 CVE-2024-34740: In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbit In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0038P3HIGHCVSS 7.8v14.0v142024-02-16
CVE-2024-0038 [HIGH] CWE-862 CVE-2024-0038: In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0050P3HIGHCVSS 7.8v12.0v12.1+6 more2024-03-11
CVE-2024-0050 [HIGH] CWE-787 CVE-2024-0050: In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a m In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a missing validation check. This could lead to a local non-security issue with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31335P3HIGHCVSS 7.8vAndroid SoC2024-07-09
CVE-2024-31335 [HIGH] CWE-783 CVE-2024-31335: In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible arbitrary code execution due to In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-40671P3HIGHCVSS 7.8vAndroid SoC2024-11-13
CVE-2024-40671 [HIGH] CWE-862 CVE-2024-40671: In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code e In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0034P3HIGHCVSS 7.8v11.0v12.0+6 more2024-02-16
CVE-2024-0034 [HIGH] CWE-276 CVE-2024-0034: In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the In BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48580P3HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48580 [HIGH] CVE-2025-48580: In connectInternal of MediaBrowser.java, there is a possible way to access while in use permission w In connectInternal of MediaBrowser.java, there is a possible way to access while in use permission while the app is in background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31316P3HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-31316 [HIGH] CVE-2024-31316: In onResult of AccountManagerService.java, there is a possible way to perform an arbitrary backgroun In onResult of AccountManagerService.java, there is a possible way to perform an arbitrary background activity launch due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34726P3HIGHCVSS 7.8vAndroid SoC2024-07-09
CVE-2024-34726 [HIGH] CWE-783 CVE-2024-34726: In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31337P3HIGHCVSS 7.8vAndroid SoC2024-11-13
CVE-2024-31337 [HIGH] CVE-2024-31337: In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper in In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34720P3HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-34720 [HIGH] CWE-783 CVE-2024-34720: In com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_Zygot In com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_ZygoteCommandBuffer.cpp, there is a possible method to perform arbitrary code execution in any app zygote processes due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User intera
nvd
CVE-2025-32327P3HIGHCVSS 7.8v14.0v15.0+2 more2025-09-04
CVE-2025-32327 [HIGH] CWE-89 CVE-2025-32327: In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQ In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23711P3HIGHCVSS 7.8vAndroid SoC2024-07-09
CVE-2024-23711 [HIGH] CWE-269 CVE-2024-23711: In DevmemXIntUnreserveRange of devicemem_server.c, there is a possible arbitrary code execution due In DevmemXIntUnreserveRange of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23696P3HIGHCVSS 7.8vAndroid SoC2024-07-09
CVE-2024-23696 [HIGH] CWE-416 CVE-2024-23696: In RGXCreateZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to a use after In RGXCreateZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23695P3HIGHCVSS 7.8vAndroid SoC2024-07-09
CVE-2024-23695 [HIGH] CWE-190 CVE-2024-23695: In CacheOpPMRExec of cache_km.c, there is a possible out of bounds write due to an integer overflow. In CacheOpPMRExec of cache_km.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23697P3HIGHCVSS 7.8vAndroid SoC2024-07-09
CVE-2024-23697 [HIGH] CWE-416 CVE-2024-23697: In RGXCreateHWRTData_aux of rgxta3d.c, there is a possible arbitrary code execution due to a use aft In RGXCreateHWRTData_aux of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35659P3HIGHCVSS 7.8vAndroid SoC2024-11-13
CVE-2023-35659 [HIGH] CVE-2023-35659: In DevmemIntChangeSparse of devicemem_server.c, there is a possible arbitrary code execution due to In DevmemIntChangeSparse of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31333P3HIGHCVSS 7.8vAndroid SoC2024-08-15
CVE-2024-31333 [HIGH] CWE-190 CVE-2024-31333: In _MMU_AllocLevel of mmu_common.c, there is a possible arbitrary code execution due to an integer o In _MMU_AllocLevel of mmu_common.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase