cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 36 of 339
CVE-2025-48620P3HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48620 [HIGH] CVE-2025-48620: In onSomePackagesChanged of VoiceInteractionManagerService.java, there is a possible way for a third In onSomePackagesChanged of VoiceInteractionManagerService.java, there is a possible way for a third party application's component name to persist even after uninstalling due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22434P3HIGHCVSS 7.8v14.0v15.0+2 more2025-09-02
CVE-2025-22434 [HIGH] CWE-693 CVE-2025-22434: In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32328P3HIGHCVSS 7.8v13.0v14.0+4 more2025-12-08
CVE-2025-32328 [HIGH] CVE-2025-32328: In multiple functions of Session.java, there is a possible way to view images belonging to a differe In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32329P3HIGHCVSS 7.8v13.0v14.0+4 more2025-12-08
CVE-2025-32329 [HIGH] CVE-2025-32329: In multiple functions of Session.java, there is a possible way to view images belonging to a differe In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48553P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48553 [HIGH] CVE-2025-48553: In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device adm In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device admin due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32333P3HIGHCVSS 7.8v14.0v142025-09-04
CVE-2025-32333 [HIGH] CWE-863 CVE-2025-32333: In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48596P3HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48596 [HIGH] CWE-125 CVE-2025-48596: In appendFrom of Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. T In appendFrom of Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22426P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2025-22426 [HIGH] CWE-284 CVE-2025-22426: In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0023P3HIGHCVSS 7.8v14.0v15.0+5 more2026-03-02
CVE-2026-0023 [HIGH] CWE-269 CVE-2026-0023: In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to upda In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48588P3HIGHCVSS 7.8v13.0v14.0+4 more2025-12-08
CVE-2025-48588 [HIGH] CVE-2025-48588: In startAlwaysOnVpn of Vpn.java, there is a possible way to disable always-on VPN due to a logic err In startAlwaysOnVpn of Vpn.java, there is a possible way to disable always-on VPN due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48606P3HIGHCVSS 7.8v16.0v16-qpr22025-12-08
CVE-2025-48606 [HIGH] CVE-2025-48606: In preparePackage of InstallPackageHelper.java, there is a possible way for an app to appear hidden In preparePackage of InstallPackageHelper.java, there is a possible way for an app to appear hidden upon installation without a mechanism to uninstall it due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32332P3HIGHCVSS 7.8vAndroid SoC2025-09-04
CVE-2025-32332 [HIGH] CWE-416 CVE-2025-32332: In multiple locations, there is a possible memory corruption due to a use after free. This could lea In multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26431P3HIGHCVSS 7.8v14.0v142025-09-04
CVE-2025-26431 [HIGH] CWE-693 CVE-2025-26431: In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enab In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0077P3HIGHCVSS 7.8v16.0-qpr2_beta_1v16.0-qpr2_beta_2+2 more2026-06-01
CVE-2026-0077 [HIGH] CWE-693 CVE-2026-0077: In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application la In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26439P3HIGHCVSS 7.8v14.0v142025-09-04
CVE-2025-26439 [HIGH] CWE-693 CVE-2025-26439: In getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious T In getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to be enabled instead of the system component due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32321P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-32321 [HIGH] CWE-441 CVE-2025-32321: In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent typ In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent type check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32326P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-32326 [HIGH] CWE-441 CVE-2025-32326: In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent secu In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2024-49730P3HIGHCVSS 7.8v13.0v14.0+2 more2025-09-02
CVE-2024-49730 [HIGH] CWE-787 CVE-2024-49730: In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47032P3HIGHCVSS 7.8vAndroid kernel2025-01-03
CVE-2024-47032 [HIGH] CWE-120 CVE-2024-47032: In construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a In construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48573P3HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48573 [HIGH] CWE-250 CVE-2025-48573: In sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service In sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service while the app is in the background due to FGS while-in-use abuse. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase