cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 57 of 339
CVE-2023-40117P3HIGHCVSS 7.8v11.0v12.0+6 more2023-10-27
CVE-2023-40117 [HIGH] CWE-863 CVE-2023-40117: In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a perm In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40116P3HIGHCVSS 7.8v11.0v12.0+4 more2023-10-27
CVE-2023-40116 [HIGH] CVE-2023-40116: In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity la In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21098P3HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21098 [HIGH] CWE-288 CVE-2023-21098: In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code i In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Androi
nvd
CVE-2023-21389P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21389 [HIGH] CWE-862 CVE-2023-21389: In Settings, there is a possible bypass of profile owner restrictions due to a missing permission ch In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21390P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21390 [HIGH] CWE-863 CVE-2023-21390: In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21388P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21388 [HIGH] CWE-862 CVE-2023-21388: In Settings, there is a possible restriction bypass due to a missing permission check. This could le In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48578P3HIGHCVSS 7.8v14.0v15.0+4 more2026-03-02
CVE-2025-48578 [HIGH] CWE-862 CVE-2025-48578: In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_ST In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-21241P3HIGHCVSS 7.8v11.0v12.0+6 more2023-07-13
CVE-2023-21241 [HIGH] CWE-190 CVE-2023-21241: In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer over In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21341P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21341 [HIGH] CWE-862 CVE-2023-21341: In Permission Manager, there is a possible way to bypass required permissions due to a missing permi In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40142P3HIGHCVSS 7.8vAndroid kernel2023-10-11
CVE-2023-40142 [HIGH] CVE-2023-40142: In TBD of TBD, there is a possible way to bypass carrier restrictions due to a logic error in the co In TBD of TBD, there is a possible way to bypass carrier restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43089P3HIGHCVSS 7.8v12.0v12.1+8 more2024-11-13
CVE-2024-43089 [HIGH] CWE-862 CVE-2024-43089: In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0026P3HIGHCVSS 7.8v14.0v142026-03-02
CVE-2026-0026 [HIGH] CWE-862 CVE-2026-0026: In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any sy In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any system permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2026-20409P3HIGHCVSS 7.8v15.02026-02-02
CVE-2026-20409 [HIGH] CWE-787 CVE-2026-20409: In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10363246; Issue ID: MSV-5779.
nvd
CVE-2026-20412P3HIGHCVSS 7.8v13.0v14.0+2 more2026-02-02
CVE-2026-20412 [HIGH] CWE-787 CVE-2026-20412: In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10351676; Issue ID: MSV-5733.
nvd
CVE-2026-20411P3HIGHCVSS 7.8v13.0v14.0+2 more2026-02-02
CVE-2026-20411 [HIGH] CWE-416 CVE-2026-20411: In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10351676; Issue ID: MSV-5737.
nvd
CVE-2018-9434P3HIGHCVSS 7.8v6.0v6.0.1+6 more2025-01-17
CVE-2018-9434 [HIGH] CWE-276 CVE-2018-9434: In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomiz In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-40661P3HIGHCVSS 7.8v12.0v12.1+6 more2024-11-13
CVE-2024-40661 [HIGH] CWE-862 CVE-2024-40661: In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to acces In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9401P3HIGHCVSS 7.8vAndroid Kernel2025-01-18
CVE-2018-9401 [HIGH] CWE-276 CVE-2018-9401: In many locations, there is a possible way to access kernel memory in user space due to an incorrect In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21375P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21375 [HIGH] CWE-190 CVE-2023-21375: In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48646P3HIGHCVSS 7.8v14.0v15.0+5 more2026-03-02
CVE-2025-48646 [HIGH] CWE-441 CVE-2025-48646: In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused dep In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
Google Android vulnerabilities | cvebase