Google Android vulnerabilities

9,646 known vulnerabilities affecting google/android.

Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2

Vulnerabilities

Page 58 of 483
CVE-2024-31319HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-31319 [HIGH] CWE-610 CVE-2024-31319: In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a po In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a possible cross-user data leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-34726HIGHCVSS 7.8vAndroid SoC2024-07-09
CVE-2024-34726 [HIGH] CWE-783 CVE-2024-34726: In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error In PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-31316HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-31316 [HIGH] CVE-2024-31316: In onResult of AccountManagerService.java, there is a possible way to perform an arbitrary backgroun In onResult of AccountManagerService.java, there is a possible way to perform an arbitrary background activity launch due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-23697HIGHCVSS 7.8vAndroid SoC2024-07-09
CVE-2024-23697 [HIGH] CWE-416 CVE-2024-23697: In RGXCreateHWRTData_aux of rgxta3d.c, there is a possible arbitrary code execution due to a use aft In RGXCreateHWRTData_aux of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-31339HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-31339 [HIGH] CWE-416 CVE-2024-31339: In multiple functions of StatsService.cpp, there is a possible memory corruption due to a use after In multiple functions of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2023-21114HIGHCVSS 7.8v13.0v132024-07-09
CVE-2023-21114 [HIGH] CWE-269 CVE-2023-21114: In multiple locations, there is a possible permission bypass due to a confused deputy. This could le In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-31324HIGHCVSS 7.3v12.0v12.1+6 more2024-07-09
CVE-2024-31324 [HIGH] CWE-1021 CVE-2024-31324: In hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by laun In hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by launching the activity in portrait mode first and then rotating it to landscape mode. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
nvdandroid
CVE-2024-34723HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-34723 [HIGH] CWE-783 CVE-2024-34723: In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to lau In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-31334HIGHCVSS 7.8vAndroid SoC2024-07-09
CVE-2024-31334 [HIGH] CWE-269 CVE-2024-31334: In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution d In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-31335HIGHCVSS 7.8vAndroid SoC2024-07-09
CVE-2024-31335 [HIGH] CWE-783 CVE-2024-31335: In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible arbitrary code execution due to In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-34725HIGHCVSS 7.0vAndroid SoC2024-07-09
CVE-2024-34725 [HIGH] CWE-362 CVE-2024-34725: In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-34720HIGHCVSS 7.8v12.0v12.1+6 more2024-07-09
CVE-2024-34720 [HIGH] CWE-783 CVE-2024-34720: In com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_Zygot In com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_ZygoteCommandBuffer.cpp, there is a possible method to perform arbitrary code execution in any app zygote processes due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User intera
nvdandroid
CVE-2024-31314MEDIUMCVSS 5.5v12.0v12.1+6 more2024-07-09
CVE-2024-31314 [MEDIUM] CWE-770 CVE-2024-31314: In multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource ex In multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-34721MEDIUMCVSS 5.5v12.0v12.1+6 more2024-07-09
CVE-2024-34721 [MEDIUM] CWE-922 CVE-2024-34721: In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-31312MEDIUMCVSS 5.5v12.0v12.1+6 more2024-07-09
CVE-2024-31312 [MEDIUM] CWE-276 CVE-2024-31312: In multiple locations, there is a possible information leak due to a missing permission check. This In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposing played media with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-20080CRITICALCVSS 9.8v13.0v14.02024-07-01
CVE-2024-20080 [CRITICAL] CWE-295 CVE-2024-20080: In gnss service, there is a possible escalation of privilege due to improper certificate validation. In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.
nvd
CVE-2024-20078CRITICALCVSS 9.8v12.0v13.0+1 more2024-07-01
CVE-2024-20078 [CRITICAL] CWE-843 CVE-2024-20078: In venc, there is a possible out of bounds write due to type confusion. This could lead to local esc In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08737250; Issue ID: MSV-1452.
nvd
CVE-2024-21461CRITICALCVSS 8.42024-07-01
CVE-2024-21461 [HIGH] CVE-2024-21461: Closed-source component Android Security Bulletin 2024-07-01 CVE: CVE-2024-21461 Severity: CRITICAL Component: Closed-source component References: A-318393487 *
android
CVE-2024-4610HIGHCVSS 7.8KEV2024-07-01
CVE-2024-4610 [HIGH] CVE-2024-4610: Mali Android Security Bulletin 2024-07-01 CVE: CVE-2024-4610 Severity: HIGH Component: Mali References: A-260126994 *
android
CVE-2024-26923HIGHCVSS 4.72024-07-01
CVE-2024-26923 [MEDIUM] CVE-2024-26923: Kernel Android Security Bulletin 2024-07-01 CVE: CVE-2024-26923 Severity: HIGH Type: EoP Component: Kernel References: A-336268889 Upstream kernel [2] [3] [4]
android