Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 49 of 339
CVE-2025-48575P3HIGHCVSS 7.8v13.0v14.0+6 more2025-12-08
CVE-2025-48575 [HIGH] CWE-862 CVE-2025-48575: In multiple functions of CertInstaller.java, there is a possible way to install certificates due to
In multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0236P3HIGHCVSS 7.5v10.0vAndroid 102021-01-26
CVE-2020-0236 [HIGH] CWE-20 CVE-2020-0236: In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper in
In A2DP_GetCodecType of a2dp_codec_config, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android, Versions: Android-10, Android ID: A-79703353.
nvd
CVE-2022-20209P3HIGHCVSS 7.5v12.1vAndroid-12L2022-06-15
CVE-2022-20209 [HIGH] CWE-787 CVE-2022-20209: In hme_add_new_node_to_a_sorted_array of hme_utils.c, there is a possible out of bounds read due to
In hme_add_new_node_to_a_sorted_array of hme_utils.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-207502397
nvd
CVE-2024-40676P3HIGHCVSS 7.7v12.0v12.1+8 more2025-01-28
CVE-2024-40676 [HIGH] CWE-843 CVE-2024-40676: In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security c
In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-2496P3CRITICALCVSS 9.8v6.0v6.0.12016-06-13
CVE-2016-2496 [CRITICAL] CWE-1021 CVE-2016-2496: The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers
The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrary private-storage files by creating a partially overlapping window, aka internal bug 26677796.
nvd
CVE-2022-20410P3HIGHCVSS 7.5v10.0v11.0+4 more2022-10-11
CVE-2022-20410 [HIGH] CWE-125 CVE-2022-20410: In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to an in
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID:
nvd
CVE-2022-20483P3HIGHCVSS 7.5v10.0v11.0+4 more2022-12-13
CVE-2022-20483 [HIGH] CWE-191 CVE-2022-20483: In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possib
In several functions that parse avrc response in avrc_pars_ct.cc and related files, there are possible out of bounds reads due to integer overflows. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12
nvd
CVE-2020-11600P3CRITICALCVSS 9.8v10.02020-04-08
CVE-2020-11600 [CRITICAL] CWE-787 CVE-2020-11600: An issue was discovered on Samsung mobile devices with Q(10.0) software. There is arbitrary code exe
An issue was discovered on Samsung mobile devices with Q(10.0) software. There is arbitrary code execution in the Fingerprint Trustlet via a memory overwrite. The Samsung IDs are SVE-2019-16587, SVE-2019-16588, SVE-2019-16589 (April 2020).
nvd
CVE-2019-20537P3CRITICALCVSS 9.8v9.02020-03-24
CVE-2019-20537 [CRITICAL] CWE-787 CVE-2019-20537: An issue was discovered on Samsung mobile devices with P(9.0) (TEEGRIS and Qualcomm chipsets). There
An issue was discovered on Samsung mobile devices with P(9.0) (TEEGRIS and Qualcomm chipsets). There is arbitrary memory overwrite in the SEM Trustlet, leading to arbitrary code execution. The Samsung IDs are SVE-2019-14651, SVE-2019-14666 (November 2019).
nvd
CVE-2020-13841P3CRITICALCVSS 9.8v9.0v10.02020-06-05
CVE-2020-13841 [CRITICAL] CVE-2020-13841: An issue was discovered on LG mobile devices with Android OS 9 and 10 (MTK chipsets). An AT command
An issue was discovered on LG mobile devices with Android OS 9 and 10 (MTK chipsets). An AT command handler allows attackers to bypass intended access restrictions. The LG ID is LVE-SMP-200009 (June 2020).
nvd
CVE-2023-21180P3HIGHCVSS 7.5v13.0vAndroid-132023-06-28
CVE-2023-21180 [HIGH] CWE-125 CVE-2023-21180: In xmlParseTryOrFinish of parser.c, there is a possible out of bounds read due to a heap buffer over
In xmlParseTryOrFinish of parser.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-261365944
nvd
CVE-2023-42717P3HIGHCVSS 7.5v11.0v12.02023-12-04
CVE-2023-42717 [HIGH] CWE-668 CVE-2023-42717: In telephony service, there is a possible missing permission check. This could lead to remote inform
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
nvd
CVE-2023-42716P3HIGHCVSS 7.5v11.0v12.02023-12-04
CVE-2023-42716 [HIGH] CWE-668 CVE-2023-42716: In telephony service, there is a possible missing permission check. This could lead to remote inform
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
nvd
CVE-2022-20445P3HIGHCVSS 7.5v10.0v11.0+4 more2022-11-08
CVE-2022-20445 [HIGH] CWE-1284 CVE-2022-20445: In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to imp
In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13An
nvd
CVE-2023-35694P3HIGHCVSS 7.5vAndroid kernel2023-07-13
CVE-2023-35694 [HIGH] CWE-125 CVE-2023-35694: In DMPixelLogger_ProcessDmCommand of DMPixelLogger.cpp, there is a possible out of bounds read due t
In DMPixelLogger_ProcessDmCommand of DMPixelLogger.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-15482P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-08-17
CVE-2018-15482 [CRITICAL] CWE-732 CVE-2018-15482: Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT applicatio
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID is LVE-SMP-180006.
nvd
CVE-2023-48404P3HIGHCVSS 7.5vAndroid kernel2023-12-08
CVE-2023-48404 [HIGH] CWE-125 CVE-2023-48404: In ProtocolMiscCarrierConfigSimInfoIndAdapter of protocolmiscadapter.cpp, there is a possible out of
In ProtocolMiscCarrierConfigSimInfoIndAdapter of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-48410P3HIGHCVSS 7.5vAndroid kernel2023-12-08
CVE-2023-48410 [HIGH] CWE-125 CVE-2023-48410: In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to a missing bounds check.
In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34727P3HIGHCVSS 7.5v12.0v12.1+6 more2024-08-15
CVE-2024-34727 [HIGH] CWE-120 CVE-2024-34727: In sdpu_compare_uuid_with_attr of sdp_utils.cc, there is a possible out of bounds read due to a heap
In sdpu_compare_uuid_with_attr of sdp_utils.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21353P3HIGHCVSS 7.5v14.0v142023-10-30
CVE-2023-21353 [HIGH] CWE-125 CVE-2023-21353: In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to rem
In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd