Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 46 of 339
CVE-2025-20706P3HIGHCVSS 7.8v14.0v15.02025-09-01
CVE-2025-20706 [HIGH] CWE-416 CVE-2025-20706: In mbrain, there is a possible memory corruption due to use after free. This could lead to local esc
In mbrain, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09924624; Issue ID: MSV-3826.
nvd
CVE-2025-20705P3HIGHCVSS 7.8v13.0v14.0+2 more2025-09-01
CVE-2025-20705 [HIGH] CWE-416 CVE-2025-20705: In monitor_hang, there is a possible memory corruption due to use after free. This could lead to loc
In monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09989078; Issue ID: MSV-3964.
nvd
CVE-2024-27221P3HIGHCVSS 7.8v13.0v132024-03-11
CVE-2024-27221 [HIGH] CWE-787 CVE-2024-27221: In update_policy_data of , there is a possible out of bounds write due to a missing bounds check. Th
In update_policy_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26444P3HIGHCVSS 7.8v13.0v14.0+2 more2025-09-04
CVE-2025-26444 [HIGH] CWE-693 CVE-2025-26444: In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the sys
In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly revert to the default assistant application when a user-selected assistant is forcibly stopped due to a logic error in the code. This could lead to local escalation of privilege where the default assistant app is automatically granted
nvd
CVE-2025-26458P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-26458 [HIGH] CWE-693 CVE-2025-26458: In multiple functions of LocationProviderManager.java, there is a possible background activity launc
In multiple functions of LocationProviderManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48546P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48546 [HIGH] CWE-693 CVE-2025-48546: In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due
In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32903P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-32903 [HIGH] CWE-787 CVE-2024-32903: In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to imp
In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32345P3HIGHCVSS 7.8v15.0v16.0+2 more2025-09-04
CVE-2025-32345 [HIGH] CWE-269 CVE-2025-32345: In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a se
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48523P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48523 [HIGH] CWE-863 CVE-2025-48523: In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permissio
In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43764P3HIGHCVSS 7.8v13.0v14.0+2 more2025-01-03
CVE-2024-43764 [HIGH] CVE-2024-43764: In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to partially bypass lock
In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to partially bypass lock screen. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-22008P3HIGHCVSS 7.8v13.0v132024-03-11
CVE-2024-22008 [HIGH] CWE-269 CVE-2024-22008: In config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds
In config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26436P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-26436 [HIGH] CWE-863 CVE-2025-26436: In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an applicatio
In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26440P3HIGHCVSS 7.8v14.0v142025-09-04
CVE-2025-26440 [HIGH] CWE-862 CVE-2025-26440: In multiple functions of CameraService.cpp, there is a possible way to use the camera from the backg
In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23713P3HIGHCVSS 7.8v12.0v12.1+6 more2024-05-07
CVE-2024-23713 [HIGH] CWE-269 CVE-2024-23713: In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to pers
In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20123P3HIGHCVSS 7.5v10.0v11.0+3 more2022-06-15
CVE-2022-20123 [HIGH] CWE-125 CVE-2022-20123: In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a
In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221
nvd
CVE-2025-20780P3HIGHCVSS 7.8v15.0v16.02026-01-06
CVE-2025-20780 [HIGH] CWE-416 CVE-2025-20780: In display, there is a possible memory corruption due to use after free. This could lead to local es
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184061; Issue ID: MSV-4712.
nvd
CVE-2025-36905P3HIGHCVSS 7.8vAndroid kernel2025-09-04
CVE-2025-36905 [HIGH] CWE-693 CVE-2025-36905: In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic erro
In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48563P3HIGHCVSS 7.8v13.0v14.0+6 more2025-09-04
CVE-2025-48563 [HIGH] CWE-453 CVE-2025-48563: In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an
In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36898P3HIGHCVSS 7.8vAndroid kernel2025-09-04
CVE-2025-36898 [HIGH] CWE-693 CVE-2025-36898: There is a possible escalation of privilege due to a logic error in the code. This could lead to loc
There is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22438P3HIGHCVSS 7.8v13.0v14.0+2 more2025-09-02
CVE-2025-22438 [HIGH] CWE-416 CVE-2025-22438: In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This
In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd