Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 38 of 339
CVE-2025-32348P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2025-32348 [HIGH] CWE-863 CVE-2025-32348: In multiple locations, there is a possible background activity launch due to a missing permission ch
In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0036P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2026-0036 [HIGH] CWE-1021 CVE-2026-0036: In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking
In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20767P3HIGHCVSS 7.8v14.0v15.0+1 more2025-12-02
CVE-2025-20767 [HIGH] CWE-787 CVE-2025-20767: In display, there is a possible out of bounds write due to an integer overflow. This could lead to l
In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4807.
nvd
CVE-2026-0099P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2026-0099 [HIGH] CWE-273 CVE-2026-0099: In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from th
In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-36935P3HIGHCVSS 7.8vAndroid kernel2025-12-11
CVE-2025-36935 [HIGH] CWE-787 CVE-2025-36935: In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to unini
In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-28577P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2026-28577 [HIGH] CWE-1021 CVE-2026-28577: In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/
In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0089P3HIGHCVSS 7.8v16.0-qpr2_beta_1v16.0-qpr2_beta_2+2 more2026-06-01
CVE-2026-0089 [HIGH] CWE-269 CVE-2026-0089: In multiple functions of PackageInstallerService.java, there is a possible way to install unverified
In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0094P3HIGHCVSS 7.8v14.0v15.0+8 more2026-06-01
CVE-2026-0094 [HIGH] CWE-451 CVE-2026-0094: In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into appr
In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-20607P3CRITICALCVSS 9.8v7.0v7.1.0+5 more2020-03-24
CVE-2019-20607 [CRITICAL] CWE-787 CVE-2019-20607: An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (MSM8996, MSM8998,
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (MSM8996, MSM8998, Exynos7420, Exynos7870, Exynos8890, and Exynos8895 chipsets) software. A heap overflow in the keymaster Trustlet allows attackers to write to TEE memory, and achieve arbitrary code execution. The Samsung ID is SVE-2019-14126 (May 2019).
nvd
CVE-2019-20588P3CRITICALCVSS 9.8v8.0v8.1+1 more2020-03-24
CVE-2019-20588 [CRITICAL] CWE-843 CVE-2019-20588: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. Th
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the SEM Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14891 (August 2019).
nvd
CVE-2019-20587P3CRITICALCVSS 9.8v8.1v9.02020-03-24
CVE-2019-20587 [CRITICAL] CWE-843 CVE-2019-20587: An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (with TEEGRIS) software. Th
An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (with TEEGRIS) software. There is type confusion in the MLDAP Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14867 (August 2019).
nvd
CVE-2019-20584P3CRITICALCVSS 9.8v8.0v8.1+1 more2020-03-24
CVE-2019-20584 [CRITICAL] CWE-843 CVE-2019-20584: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. Th
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the HDCP Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14850 (August 2019).
nvd
CVE-2019-20585P3CRITICALCVSS 9.8v8.0v8.1+1 more2020-03-24
CVE-2019-20585 [CRITICAL] CWE-843 CVE-2019-20585: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. Th
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the SEC_FR Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14851 (August 2019).
nvd
CVE-2019-20589P3CRITICALCVSS 9.8v8.0v8.1+1 more2020-03-24
CVE-2019-20589 [CRITICAL] CWE-843 CVE-2019-20589: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. Th
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the SKPM Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14892 (August 2019).
nvd
CVE-2019-20586P3CRITICALCVSS 9.8v8.1v9.02020-03-24
CVE-2019-20586 [CRITICAL] CWE-843 CVE-2019-20586: An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (with TEEGRIS) software. Th
An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (with TEEGRIS) software. There is type confusion in the FINGERPRINT Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14864 (August 2019).
nvd
CVE-2019-20583P3CRITICALCVSS 9.8v8.0v8.1+1 more2020-03-24
CVE-2019-20583 [CRITICAL] CWE-843 CVE-2019-20583: An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. Th
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the EXT_FR Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14847 (August 2019).
nvd
CVE-2025-48635P3HIGHCVSS 7.7v14.0v15.0+2 more2026-03-02
CVE-2025-48635 [HIGH] CWE-200 CVE-2025-48635: In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token le
In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0017P3HIGHCVSS 7.7v16.0v16-qpr2+1 more2026-03-02
CVE-2026-0017 [HIGH] CWE-285 CVE-2026-0017: In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a
In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29743P3HIGHCVSS 7.7vAndroid kernel2024-04-05
CVE-2024-29743 [HIGH] CWE-787 CVE-2024-29743: In tmu_set_temp_lut of tmu.c, there is a possible out of bounds write due to a missing bounds check.
In tmu_set_temp_lut of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29753P3HIGHCVSS 7.7vAndroid kernel2024-04-05
CVE-2024-29753 [HIGH] CWE-787 CVE-2024-29753: In tmu_set_control_temp_step of tmu.c, there is a possible out of bounds write due to a missing boun
In tmu_set_control_temp_step of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd