Google Android vulnerabilities

9,646 known vulnerabilities affecting google/android.

Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2

Vulnerabilities

Page 55 of 483
CVE-2024-34743HIGHCVSS 7.8v14.0v142024-08-15
CVE-2024-34743 [HIGH] CWE-1021 CVE-2024-34743: In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-34737HIGHCVSS 7.8v12.0v12.1+6 more2024-08-15
CVE-2024-34737 [HIGH] CVE-2024-34737: In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-34736HIGHCVSS 7.8v12.0v12.1+6 more2024-08-15
CVE-2024-34736 [HIGH] CVE-2024-34736: In setupVideoEncoder of StagefrightRecorder.cpp, there is a possible asynchronous playback when B-fr In setupVideoEncoder of StagefrightRecorder.cpp, there is a possible asynchronous playback when B-frame support is enabled. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-34738HIGHCVSS 7.8v13.0v14.0+2 more2024-08-15
CVE-2024-34738 [HIGH] CWE-266 CVE-2024-34738: In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read t In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-34734HIGHCVSS 7.8v13.0v14.0+2 more2024-08-15
CVE-2024-34734 [HIGH] CWE-1188 CVE-2024-34734: In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-34742MEDIUMCVSS 5.5v14.0v142024-08-15
CVE-2024-34742 [MEDIUM] CWE-843 CVE-2024-34742: In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from bei In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-20083CRITICALCVSS 9.8v12.02024-08-14
CVE-2024-20083 [CRITICAL] CWE-787 CVE-2024-20083: In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to l In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08810810 / ALPS08805789; Issue ID: MSV-1502.
nvd
CVE-2024-23350CRITICALCVSS 6.52024-08-01
CVE-2024-23350 [MEDIUM] CVE-2024-23350: Closed-source component Android Security Bulletin 2024-08-01 CVE: CVE-2024-23350 Severity: CRITICAL Component: Closed-source component References: A-323919259 *
android
CVE-2024-21478HIGHCVSS 6.22024-08-01
CVE-2024-21478 [MEDIUM] CVE-2024-21478: Display Android Security Bulletin 2024-08-01 CVE: CVE-2024-21478 Severity: HIGH Component: Display References: A-323926460 QC-CR#3594987
android
CVE-2024-33011HIGHCVSS 7.52024-08-01
CVE-2024-33011 [HIGH] CVE-2024-33011: WLAN Android Security Bulletin 2024-08-01 CVE: CVE-2024-33011 Severity: HIGH Component: WLAN References: A-339043727 QC-CR#3717567
android
CVE-2024-23353HIGHCVSS 7.52024-08-01
CVE-2024-23353 [HIGH] CVE-2024-23353: Closed-source component Android Security Bulletin 2024-08-01 CVE: CVE-2024-23353 Severity: HIGH Component: Closed-source component References: A-323918845 *
android
CVE-2024-23382HIGHCVSS 8.42024-08-01
CVE-2024-23382 [HIGH] CVE-2024-23382: Display Android Security Bulletin 2024-08-01 CVE: CVE-2024-23382 Severity: HIGH Component: Display References: A-339043615 QC-CR#3704061 [2]
android
CVE-2024-33018HIGHCVSS 7.52024-08-01
CVE-2024-33018 [HIGH] CVE-2024-33018: WLAN Android Security Bulletin 2024-08-01 CVE: CVE-2024-33018 Severity: HIGH Component: WLAN References: A-339043500 QC-CR#3704796
android
CVE-2024-33019HIGHCVSS 7.52024-08-01
CVE-2024-33019 [HIGH] CVE-2024-33019: WLAN Android Security Bulletin 2024-08-01 CVE: CVE-2024-33019 Severity: HIGH Component: WLAN References: A-339043783 QC-CR#3704794
android
CVE-2024-33023HIGHCVSS 8.42024-08-01
CVE-2024-33023 [HIGH] CVE-2024-33023: Display Android Security Bulletin 2024-08-01 CVE: CVE-2024-33023 Severity: HIGH Component: Display References: A-339043278 QC-CR#3702019 [2]
android
CVE-2024-23352HIGHCVSS 7.52024-08-01
CVE-2024-23352 [HIGH] CVE-2024-23352: Closed-source component Android Security Bulletin 2024-08-01 CVE: CVE-2024-23352 Severity: HIGH Component: Closed-source component References: A-323918787 *
android
CVE-2024-23384HIGHCVSS 8.42024-08-01
CVE-2024-23384 [HIGH] CVE-2024-23384: Display Android Security Bulletin 2024-08-01 CVE: CVE-2024-23384 Severity: HIGH Component: Display References: A-339043323 QC-CR#3704870 [2] [3] [4]
android
CVE-2024-2937HIGHCVSS 7.82024-08-01
CVE-2024-2937 [HIGH] CVE-2024-2937: Mali Android Security Bulletin 2024-08-01 CVE: CVE-2024-2937 Severity: HIGH Component: Mali References: A-339866012 *
android
CVE-2024-33024HIGHCVSS 7.52024-08-01
CVE-2024-33024 [HIGH] CVE-2024-33024: WLAN Android Security Bulletin 2024-08-01 CVE: CVE-2024-33024 Severity: HIGH Component: WLAN References: A-339043270 QC-CR#3700072
android
CVE-2024-33027HIGHCVSS 8.42024-08-01
CVE-2024-33027 [HIGH] CVE-2024-33027: Display Android Security Bulletin 2024-08-01 CVE: CVE-2024-33027 Severity: HIGH Component: Display References: A-316373168 QC-CR#3697522
android