cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 45 of 339
CVE-2025-48522P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48522 [HIGH] CWE-693 CVE-2025-48522: In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM assoc In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49720P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-02
CVE-2024-49720 [HIGH] CWE-693 CVE-2024-49720: In multiple functions of Permissions.java, there is a possible way to override the state of the user In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21381P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21381 [HIGH] CWE-416 CVE-2023-21381: In Media Resource Manager, there is a possible local arbitrary code execution due to use after free. In Media Resource Manager, there is a possible local arbitrary code execution due to use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40120P3HIGHCVSS 7.8v11.0v12.0+6 more2023-10-27
CVE-2023-40120 [HIGH] CVE-2023-40120: In multiple locations, there is a possible way to bypass user notification of foreground services du In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-0080P3HIGHCVSS 7.8v15.0v152025-08-26
CVE-2025-0080 [HIGH] CWE-250 CVE-2025-0080: In multiple locations, there is a possible way to overlay the installation confirmation dialog due t In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20064P3HIGHCVSS 7.8v13.0v14.02024-05-06
CVE-2024-20064 [HIGH] CWE-20 CVE-2024-20064: In wlan service, there is a possible out of bounds write due to improper input validation. This coul In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08572601; Issue ID: MSV-1229.
nvd
CVE-2024-29752P3HIGHCVSS 7.8vAndroid kernel2024-04-05
CVE-2024-29752 [HIGH] CWE-787 CVE-2024-29752: In tmu_set_tr_num_thresholds of tmu.c, there is a possible out of bounds write due to a missing boun In tmu_set_tr_num_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21247P3HIGHCVSS 7.8v12.0v12.1+4 more2023-07-13
CVE-2023-21247 [HIGH] CWE-862 CVE-2023-21247: In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possibl In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21248P3HIGHCVSS 7.8v12.0v12.1+4 more2023-07-13
CVE-2023-21248 [HIGH] CWE-862 CVE-2023-21248: In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48540P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48540 [HIGH] CWE-787 CVE-2025-48540: In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a l In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2017-13323P3HIGHCVSS 7.8v6.0v6.0.1+8 more2024-11-27
CVE-2017-13323 [HIGH] CWE-190 CVE-2017-13323: In String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow. Thi In String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9474P3HIGHCVSS 7.8v7.0v7.1.1+9 more2024-11-20
CVE-2018-9474 [HIGH] CWE-502 CVE-2018-9474: In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9366P3HIGHCVSS 7.8vSoCVersion2024-11-19
CVE-2018-9366 [HIGH] CWE-190 CVE-2018-9366: In IMSA_Recv_Thread and VT_IMCB_Thread of ImsaClient.cpp and VideoTelephony.c, there is a possible o In IMSA_Recv_Thread and VT_IMCB_Thread of ImsaClient.cpp and VideoTelephony.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9372P3HIGHCVSS 7.8vSoCVersion2024-11-19
CVE-2018-9372 [HIGH] CWE-787 CVE-2018-9372: In cmd_flash_mmc_sparse_img of dl_commands.c, there is a possible out of bounds write due to a missi In cmd_flash_mmc_sparse_img of dl_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to a local escalation of privilege in the bootloader with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9367P3HIGHCVSS 7.8vSoCVersion2024-11-19
CVE-2018-9367 [HIGH] CWE-787 CVE-2018-9367: In FT_ACDK_CCT_V2_OP_ISP_SET_TUNING_PARAS of Meta_CCAP_Para.cpp, there is a possible out of bounds w In FT_ACDK_CCT_V2_OP_ISP_SET_TUNING_PARAS of Meta_CCAP_Para.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9409P3HIGHCVSS 7.8v8.12024-11-19
CVE-2018-9409 [HIGH] CWE-787 CVE-2018-9409: In HWCSession::SetColorModeById of hwc_session.cpp, there is a possible out of bounds write due to a In HWCSession::SetColorModeById of hwc_session.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23710P3HIGHCVSS 7.8v13.0v14.0+2 more2024-05-07
CVE-2024-23710 [HIGH] CWE-269 CVE-2024-23710: In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execu In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48589P3HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48589 [HIGH] CVE-2025-48589: In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissio In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26454P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-26454 [HIGH] CWE-441 CVE-2025-26454: In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another user due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32349P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-32349 [HIGH] CWE-1021 CVE-2025-32349: In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase