cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 37 of 339
CVE-2025-32347P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-32347 [HIGH] CWE-926 CVE-2025-32347: In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's lo In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2026-0009P3HIGHCVSS 7.8v15.0v16.0+2 more2026-06-01
CVE-2026-0009 [HIGH] CWE-269 CVE-2026-0009: In multiple locations, there is a possible tapjacking due to a logic error in the code. This could l In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48586P3HIGHCVSS 7.8v15.0v16.0+2 more2025-12-08
CVE-2025-48586 [HIGH] CWE-441 CVE-2025-48586: In onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from the In onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from the work profile due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48649P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2025-48649 [HIGH] CWE-693 CVE-2025-48649: In multiple locations, there is a possible way to reset user-selected permissions selections due to In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0076P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2026-0076 [HIGH] CWE-125 CVE-2026-0076: In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bou In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48627P3HIGHCVSS 7.8v13.0v14.0+2 more2025-12-08
CVE-2025-48627 [HIGH] CVE-2025-48627: In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to launch a In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48536P3HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48536 [HIGH] CWE-441 CVE-2025-48536: In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a t In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to modify secure settings due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36887P3HIGHCVSS 7.8vAndroid kernel2025-09-04
CVE-2025-36887 [HIGH] CWE-787 CVE-2025-36887: In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds writ In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36903P3HIGHCVSS 7.8vAndroid kernel2025-09-04
CVE-2025-36903 [HIGH] CWE-787 CVE-2025-36903: In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This c In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49737P3HIGHCVSS 7.8v13.0v14.0+4 more2025-01-21
CVE-2024-49737 [HIGH] CWE-276 CVE-2024-49737: In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch a In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26452P3HIGHCVSS 7.8v14.0v15.0+2 more2025-09-04
CVE-2025-26452 [HIGH] CWE-441 CVE-2025-26452: In loadDrawableForCookie of ResourcesImpl.java, there is a possible way to access task snapshots of In loadDrawableForCookie of ResourcesImpl.java, there is a possible way to access task snapshots of other apps due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22414P3HIGHCVSS 7.8v13.0v14.0+2 more2025-09-04
CVE-2025-22414 [HIGH] CWE-862 CVE-2025-22414: In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26450P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-26450 [HIGH] CWE-862 CVE-2025-26450: In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to In onInputEvent of IInputMethodSessionWrapper.java, there is a possible way for an untrusted app to inject key and motion events to the default IME due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48629P3HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48629 [HIGH] CWE-1188 CVE-2025-48629: In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech recognizer app due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48599P3HIGHCVSS 7.8v13.0v14.0+2 more2025-12-08
CVE-2025-48599 [HIGH] CWE-862 CVE-2025-48599: In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device confi In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-3743P3CRITICALCVSS 9.8v6.0v6.0.12016-07-11
CVE-2016-3743 [CRITICAL] CWE-20 CVE-2016-3743: decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-07-01 does not initialize certain dat decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-07-01 does not initialize certain data structures, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 27907656.
nvd
CVE-2016-3742P3CRITICALCVSS 9.8v6.0v6.0.12016-07-11
CVE-2016-3742 [CRITICAL] CWE-20 CVE-2016-3742: decoder/ih264d_process_intra_mb.c in mediaserver in Android 6.x before 2016-07-01 mishandles intra m decoder/ih264d_process_intra_mb.c in mediaserver in Android 6.x before 2016-07-01 mishandles intra mode, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 28165659.
nvd
CVE-2025-48628P3HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48628 [HIGH] CWE-441 CVE-2025-48628: In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak d In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32320P3HIGHCVSS 7.8v16.0v162025-09-05
CVE-2025-32320 [HIGH] CWE-441 CVE-2025-32320: In System UI, there is a possible way to view other users' images due to a confused deputy. This cou In System UI, there is a possible way to view other users' images due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48570P3HIGHCVSS 7.8v14.0v142026-06-01
CVE-2025-48570 [HIGH] CWE-441 CVE-2025-48570: In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from t In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase