Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 56 of 339
CVE-2024-34719P3HIGHCVSS 7.8v12.0v12.1+6 more2024-11-13
CVE-2024-34719 [HIGH] CWE-476 CVE-2024-34719: In multiple locations, there is a possible permissions bypass due to a missing null check. This coul
In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-40660P3HIGHCVSS 7.8v14.0v15.0+2 more2024-11-13
CVE-2024-40660 [HIGH] CWE-276 CVE-2024-40660: In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display at
In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34747P3HIGHCVSS 7.8vAndroid SoC2024-11-13
CVE-2024-34747 [HIGH] CWE-416 CVE-2024-34747: In DevmemXIntMapPages of devicemem_server.c, there is a possible use-after-free due to a logic error
In DevmemXIntMapPages of devicemem_server.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-39798P3HIGHCVSS 7.8v12.0v12.1+1 more2022-04-12
CVE-2021-39798 [HIGH] CWE-119 CVE-2021-39798: In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a miss
In Bitmap_createFromParcel of Bitmap.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-213169612
nvd
CVE-2021-1027P3HIGHCVSS 7.8v12.0vAndroid-122021-12-15
CVE-2021-1027 [HIGH] CWE-704 CVE-2021-1027: In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged
In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged process due to improper casting. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-193033243
nvd
CVE-2021-39810P3HIGHCVSS 7.8v13.0v132023-10-30
CVE-2021-39810 [HIGH] CWE-862 CVE-2021-39810: In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as
In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40130P3HIGHCVSS 7.8v11.0v12.0+6 more2023-10-27
CVE-2023-40130 [HIGH] CVE-2023-40130: In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic e
In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0042P3HIGHCVSS 7.8vAndroid SoC2024-05-07
CVE-2024-0042 [HIGH] CWE-295 CVE-2024-0042: In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used cryp
In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM content protection with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48567P3HIGHCVSS 7.8v14.0v15.0+4 more2026-03-02
CVE-2025-48567 [HIGH] CWE-22 CVE-2025-48567: In multiple locations, there is a possible bypass of a file path filter designed to prevent access t
In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-48549P3HIGHCVSS 7.8v13.0v14.0+4 more2025-09-04
CVE-2025-48549 [HIGH] CWE-862 CVE-2025-48549: In multiple locations, there is a possible way to record audio via a background app due to a missing
In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31325P3HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-31325 [HIGH] CWE-269 CVE-2024-31325: In multiple locations, there is a possible way to reveal images across users data due to a logic err
In multiple locations, there is a possible way to reveal images across users data due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-0025P3HIGHCVSS 7.8v12.0v12.1+6 more2024-05-07
CVE-2024-0025 [HIGH] CWE-284 CVE-2024-0025: In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch d
In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20419P3HIGHCVSS 7.8v12.1v13.0+1 more2022-10-11
CVE-2022-20419 [HIGH] CVE-2022-20419: In setOptions of ActivityRecord.java, there is a possible load any arbitrary Java code into launcher
In setOptions of ActivityRecord.java, there is a possible load any arbitrary Java code into launcher process due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-237290578
nvd
CVE-2023-48421P3HIGHCVSS 7.8vAndroid kernel2023-12-08
CVE-2023-48421 [HIGH] CWE-787 CVE-2023-48421: In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/platform/p
In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/platform/pixel/pixel_gpu_slc.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-23706P3HIGHCVSS 7.8v14.0v142024-05-07
CVE-2024-23706 [HIGH] CWE-20 CVE-2024-23706: In multiple locations, there is a possible bypass of health data permissions due to an improper inpu
In multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-25992P3HIGHCVSS 7.8v13.0v132024-03-11
CVE-2024-25992 [HIGH] CWE-125 CVE-2024-25992: In tmu_tz_control of tmu.c, there is a possible out of bounds read due to a missing bounds check. Th
In tmu_tz_control of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-30755P3HIGHCVSS 7.8v10.0v11.0+1 more2022-07-12
CVE-2022-30755 [HIGH] CWE-287 CVE-2022-30755: Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to
Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.
nvd
CVE-2018-9464P3HIGHCVSS 7.8vAndroid Kernel2025-01-18
CVE-2018-9464 [HIGH] CWE-125 CVE-2018-9464: In multiple locations, there is a possible way to read protected files due to a missing permission c
In multiple locations, there is a possible way to read protected files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9387P3HIGHCVSS 7.8vAndroid Kernel2025-01-18
CVE-2018-9387 [HIGH] CWE-120 CVE-2018-9387: In multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an inte
In multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-31332P3HIGHCVSS 7.8v13.0v14.0+2 more2024-07-09
CVE-2024-31332 [HIGH] CWE-862 CVE-2024-31332: In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connectio
In multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd