cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 47 of 339
CVE-2025-22438P3HIGHCVSS 7.8v13.0v14.0+2 more2025-09-02
CVE-2025-22438 [HIGH] CWE-416 CVE-2025-22438: In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32907P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-32907 [HIGH] CWE-120 CVE-2024-32907: In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. Th In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32350P3HIGHCVSS 7.8v14.0v15.0+4 more2025-09-04
CVE-2025-32350 [HIGH] CWE-1021 CVE-2025-32350: In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsS In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32901P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-32901 [HIGH] CWE-787 CVE-2024-32901: In v4l2_smfc_qbuf of smfc-v4l2-ioctls.c, there is a possible out of bounds write due to a missing bo In v4l2_smfc_qbuf of smfc-v4l2-ioctls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-29784P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-29784 [HIGH] CWE-190 CVE-2024-29784: In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-56192P3HIGHCVSS 7.8vunknown2025-03-10
CVE-2024-56192 [HIGH] CWE-281 CVE-2024-56192: In wl_notify_gscan_event of wl_cfgscan.c, there is a possible out of bounds write due to a missing b In wl_notify_gscan_event of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-53837P3HIGHCVSS 7.8vAndroid kernel2025-01-03
CVE-2024-53837 [HIGH] CWE-787 CVE-2024-53837: In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-53838P3HIGHCVSS 7.8vAndroid kernel2025-01-03
CVE-2024-53838 [HIGH] CWE-787 CVE-2024-53838: In Exynos_parsing_user_data_registered_itu_t_t35 of VendorVideoAPI.cpp, there is a possible out of b In Exynos_parsing_user_data_registered_itu_t_t35 of VendorVideoAPI.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-53833P3HIGHCVSS 7.8vAndroid kernel2025-01-03
CVE-2024-53833 [HIGH] CWE-787 CVE-2024-53833: In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to im In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9414P3HIGHCVSS 7.8v6.0v6.0.1+8 more2024-12-02
CVE-2018-9414 [HIGH] CWE-787 CVE-2018-9414: In gattServerSendResponseNative of com_android_bluetooth_gatt.cpp, there is a possible out of bounds In gattServerSendResponseNative of com_android_bluetooth_gatt.cpp, there is a possible out of bounds stack write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9424P3HIGHCVSS 7.8v8.0v8.1+1 more2024-11-19
CVE-2018-9424 [HIGH] CWE-787 CVE-2018-9424: In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missi In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47012P3HIGHCVSS 7.8vAndroid kernel2024-10-25
CVE-2024-47012 [HIGH] CWE-787 CVE-2024-47012: In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due t In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27210P3HIGHCVSS 7.8v13.0v132024-03-11
CVE-2024-27210 [HIGH] CWE-269 CVE-2024-27210: In policy_check of fvp.c, there is a possible out of bounds write due to a missing bounds check. Thi In policy_check of fvp.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27224P3HIGHCVSS 7.8v13.0v132024-03-11
CVE-2024-27224 [HIGH] CWE-269 CVE-2024-27224: In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26462P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-26462 [HIGH] CWE-269 CVE-2025-26462: In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logi In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26430P3HIGHCVSS 7.8v15.0v152025-09-04
CVE-2025-26430 [HIGH] CWE-285 CVE-2025-26430: In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-26435P3HIGHCVSS 7.8v15.0v152025-09-04
CVE-2025-26435 [HIGH] CWE-269 CVE-2025-26435: In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a se In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22428P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-02
CVE-2025-22428 [HIGH] CWE-863 CVE-2025-22428: In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permis In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the primary user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43077P3HIGHCVSS 7.8vAndroid SoC2025-01-03
CVE-2024-43077 [HIGH] CWE-787 CVE-2024-43077: In DevmemValidateFlags of devicemem_server.c , there is a possible out of bounds write due to memory In DevmemValidateFlags of devicemem_server.c , there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47035P3HIGHCVSS 7.8vAndroid kernel2024-10-25
CVE-2024-47035 [HIGH] CWE-787 CVE-2024-47035: In vring_init of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds wr In vring_init of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase