cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 35 of 339
CVE-2024-31336P3HIGHCVSS 7.8vAndroid SoC2024-09-11
CVE-2024-31336 [HIGH] CWE-787 CVE-2024-31336: In PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution In PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31334P3HIGHCVSS 7.8vAndroid SoC2024-07-09
CVE-2024-31334 [HIGH] CWE-269 CVE-2024-31334: In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution d In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48653P3HIGHCVSS 7.8v14.0v15.0+5 more2026-03-02
CVE-2025-48653 [HIGH] CWE-693 CVE-2025-48653: In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due t In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48654P3HIGHCVSS 7.8v16.0v16-qpr2+1 more2026-03-02
CVE-2025-48654 [HIGH] CWE-610 CVE-2025-48654: In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic In onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48615P3HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48615 [HIGH] CWE-770 CVE-2025-48615: In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35686P3HIGHCVSS 7.8vAndroid SoC2024-11-13
CVE-2023-35686 [HIGH] CVE-2023-35686: In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper in In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48637P3HIGHCVSS 7.8vAndroid kernel2025-12-08
CVE-2025-48637 [HIGH] CWE-190 CVE-2025-48637: In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer ov In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48552P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48552 [HIGH] CVE-2025-48552: In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from persistence due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36918P3HIGHCVSS 7.8vAndroid kernel2025-12-11
CVE-2025-36918 [HIGH] CWE-125 CVE-2025-36918: In aoc_service_read_message of aoc_ipc_core.c, there is a possible out of bounds read due to imprope In aoc_service_read_message of aoc_ipc_core.c, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48544P3HIGHCVSS 7.8v13.0v14.0+5 more2025-09-04
CVE-2025-48544 [HIGH] CWE-89 CVE-2025-48544: In multiple locations, there is a possible way to read files belonging to other apps due to SQL inje In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48531P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48531 [HIGH] CWE-693 CVE-2025-48531: In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22422P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-02
CVE-2025-22422 [HIGH] CWE-639 CVE-2025-22422: In multiple locations, there is a possible way to mislead a user into approving an authentication pr In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app when its result will be used in another due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32312P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-32312 [HIGH] CWE-502 CVE-2025-32312: In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified data to be passed to the next process due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26455P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-26455 [HIGH] CWE-122 CVE-2025-26455: In multiple functions of NdkMediaCodec.cpp, there is a possible out of bounds write due to a heap bu In multiple functions of NdkMediaCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22433P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-02
CVE-2025-22433 [HIGH] CWE-693 CVE-2025-22433: In canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile inten In canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most commonly used in Work Profile scenarios due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9368P3HIGHCVSS 7.8vSoCVersion2024-11-19
CVE-2018-9368 [HIGH] CWE-787 CVE-2018-9368: In mtkscoaudio debugfs there is a possible arbitrary kernel memory write due to missing bounds check In mtkscoaudio debugfs there is a possible arbitrary kernel memory write due to missing bounds check and weakened SELinux policies. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48624P3HIGHCVSS 7.8vAndroid kernel2025-12-08
CVE-2025-48624 [HIGH] CWE-787 CVE-2025-48624: In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper inpu In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32323P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-32323 [HIGH] CWE-20 CVE-2025-32323: In getCallingAppName of Shared.java, there is a possible way to trick users into granting file acces In getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text in a permission popup due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21165P3HIGHCVSS 7.8vAndroid SoC2024-02-16
CVE-2023-21165 [HIGH] CWE-416 CVE-2023-21165: In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a us In DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36928P3HIGHCVSS 7.8vAndroid kernel2025-12-11
CVE-2025-36928 [HIGH] CWE-120 CVE-2025-36928: In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to an incorrect bound In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase