Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 51 of 339
CVE-2025-61619P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-01
CVE-2025-61619 [HIGH] CVE-2025-61619: In nr modem, there is a possible system crash due to improper input validation. This could lead to r
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
nvd
CVE-2025-11133P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-01
CVE-2025-11133 [HIGH] CVE-2025-11133: In nr modem, there is a possible system crash due to improper input validation. This could lead to r
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
nvd
CVE-2025-69279P3HIGHCVSS 7.5v13.0v14.0+2 more2026-03-09
CVE-2025-69279 [HIGH] CWE-20 CVE-2025-69279: In nr modem, there is a possible system crash due to improper input validation. This could lead to r
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
CVE-2025-69278P3HIGHCVSS 7.5v13.0v14.0+2 more2026-03-09
CVE-2025-69278 [HIGH] CWE-20 CVE-2025-69278: In nr modem, there is a possible system crash due to improper input validation. This could lead to r
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
nvd
CVE-2020-25283P3CRITICALCVSS 9.8v8.0v8.1+2 more2020-09-11
CVE-2020-25283 [CRITICAL] CWE-862 CVE-2020-25283: An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT mana
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers to bypass intended access restrictions on a certain mode. The LG ID is LVE-SMP-200021 (September 2020).
nvd
CVE-2024-47021P3HIGHCVSS 7.5vAndroid kernel2024-10-25
CVE-2024-47021 [HIGH] CWE-125 CVE-2024-47021: In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a mis
In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-25478P3HIGHCVSS 7.2v8.1v9.0+2 more2021-10-06
CVE-2021-25478 [HIGH] CWE-121 CVE-2021-25478: A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Rele
A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.
nvd
CVE-2023-35691P3HIGHCVSS 7.2vAndroid kernel2023-07-13
CVE-2023-35691 [HIGH] CWE-125 CVE-2023-35691: there is a possible out of bounds read due to a missing bounds check. This could lead to remote deni
there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with System execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20057P3HIGHCVSS 7.2v12.0v13.0+1 more2024-05-06
CVE-2024-20057 [HIGH] CWE-787 CVE-2024-20057: In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lea
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ID: ALPS08587881.
nvd
CVE-2017-18648P3CRITICALCVSS 9.1v4.4v4.4.1+15 more2020-04-07
CVE-2017-18648 [CRITICAL] CWE-20 CVE-2017-18648: An issue was discovered on Samsung mobile devices with KK(4.4.x), L(5.x), M(6.x), and N(7.x) softwar
An issue was discovered on Samsung mobile devices with KK(4.4.x), L(5.x), M(6.x), and N(7.x) software. Arbitrary file read/write operations can occur in the locked state via a crafted MTP command. The Samsung ID is SVE-2017-10086 (November 2017).
nvd
CVE-2019-1994P3HIGHCVSS 8.8v8.0v8.1+1 more2019-02-28
CVE-2019-1994 [HIGH] CWE-1188 CVE-2019-1994: In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings access
In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insecure default value. This could lead to unwanted access to development settings, with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9.
nvd
CVE-2015-1474P3CRITICALCVSS 10.0≤ 5.02015-02-16
CVE-2015-1474 [CRITICAL] CWE-189 CVE-2015-1474: Multiple integer overflows in the GraphicBuffer::unflatten function in platform/frameworks/native/li
Multiple integer overflows in the GraphicBuffer::unflatten function in platform/frameworks/native/libs/ui/GraphicBuffer.cpp in Android through 5.0 allow attackers to gain privileges or cause a denial of service (memory corruption) via vectors that trigger a large number of (1) file descriptors or (2) integer values.
nvd
CVE-2019-2029P3HIGHCVSS 8.8v7.0v7.1.1+4 more2019-04-19
CVE-2019-2029 [HIGH] CWE-416 CVE-2019-2029: In btm_proc_smp_cback of tm_ble.cc, there is a possible memory corruption due to a use after free. T
In btm_proc_smp_cback of tm_ble.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-12061
nvd
CVE-2016-0809P3HIGHCVSS 8.8v6.0v6.0.12016-02-07
CVE-2016-0809 [HIGH] CWE-264 CVE-2016-0809: Use-after-free vulnerability in the wifi_cleanup function in bcmdhd/wifi_hal/wifi_hal.cpp in Wi-Fi i
Use-after-free vulnerability in the wifi_cleanup function in bcmdhd/wifi_hal/wifi_hal.cpp in Wi-Fi in Android 6.x before 2016-02-01 allows attackers to gain privileges by leveraging access to the local physical environment during execution of a crafted application, aka internal bug 25753768.
nvd
CVE-2020-35693P3HIGHCVSS 8.8≤ 7.1.12020-12-24
CVE-2020-35693 [HIGH] CVE-2020-35693: On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-con
On some Samsung phones and tablets running Android through 7.1.1, it is possible for an attacker-controlled Bluetooth Low Energy (BLE) device to pair silently with a vulnerable target device, without any user interaction, when the target device's Bluetooth is on, and it is running an app that offers a connectable BLE advertisement. An example of such an app c
nvd
CVE-2017-0786P3HIGHCVSS 8.8v7.1.22017-09-08
CVE-2017-0786 [HIGH] CVE-2017-0786: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37351060. References: B-V2017060101.
nvd
CVE-2017-0787P3HIGHCVSS 8.8v7.1.22017-09-08
CVE-2017-0787 [HIGH] CVE-2017-0787: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37722970. References: B-V2017053104.
nvd
CVE-2017-0789P3HIGHCVSS 8.8v7.1.22017-09-08
CVE-2017-0789 [HIGH] CVE-2017-0789: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37685267. References: B-V2017053102.
nvd
CVE-2017-0790P3HIGHCVSS 8.8v7.1.22017-09-08
CVE-2017-0790 [HIGH] CVE-2017-0790: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37357704. References: B-V2017053101.
nvd
CVE-2017-0791P3HIGHCVSS 8.8v7.1.22017-09-08
CVE-2017-0791 [HIGH] CVE-2017-0791: A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: And
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37306719. References: B-V2017052302.
nvd