Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 58 of 339
CVE-2024-23704P3HIGHCVSS 7.8v13.0v14.0+2 more2024-05-07
CVE-2024-23704 [HIGH] CWE-862 CVE-2024-23704: In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONF
In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40125P3HIGHCVSS 7.8v11.0v12.0+6 more2023-10-27
CVE-2023-40125 [HIGH] CVE-2023-40125: In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a p
In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34737P3HIGHCVSS 7.8v12.0v12.1+6 more2024-08-15
CVE-2024-34737 [HIGH] CVE-2024-34737: In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to
In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40141P3HIGHCVSS 7.8vAndroid kernel2023-10-11
CVE-2023-40141 [HIGH] CWE-787 CVE-2023-40141: In temp_residency_name_store of thermal_metrics.c, there is a possible out of bounds write due to a
In temp_residency_name_store of thermal_metrics.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21229P3HIGHCVSS 7.8v11.0v13.0+2 more2023-08-14
CVE-2023-21229 [HIGH] CVE-2023-21229: In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity
In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21145P3HIGHCVSS 7.8v11.0v12.0+6 more2023-07-13
CVE-2023-21145 [HIGH] CWE-326 CVE-2023-21145: In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launc
In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-53841P3HIGHCVSS 7.8vAndroid kernel2025-01-03
CVE-2024-53841 [HIGH] CWE-276 CVE-2024-53841: In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused depu
In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9339P3HIGHCVSS 7.8v8.0v8.1+1 more2024-11-19
CVE-2018-9339 [HIGH] CWE-843 CVE-2018-9339: In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of priv
In writeTypedArrayList and readTypedArrayList of Parcel.java, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32906P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-32906 [HIGH] CWE-908 CVE-2024-32906: In AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to
In AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32908P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-32908 [HIGH] CWE-362 CVE-2024-32908: In sec_media_protect of media.c, there is a possible permission bypass due to a race condition. This
In sec_media_protect of media.c, there is a possible permission bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21374P3HIGHCVSS 7.8v14.0v142023-10-30
CVE-2023-21374 [HIGH] CWE-269 CVE-2023-21374: In System UI, there is a possible factory reset protection bypass due to a logic error in the code.
In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21131P3HIGHCVSS 7.8v11.0v12.0+3 more2023-06-15
CVE-2023-21131 [HIGH] CWE-639 CVE-2023-21131: In checkKeyIntentParceledCorrectly() of ActivityManagerService.java, there is a possible bypass of P
In checkKeyIntentParceledCorrectly() of ActivityManagerService.java, there is a possible bypass of Parcel Mismatch mitigations due to a logic error in the code. This could lead to local escalation of privilege and the ability to launch arbitrary activities in settings with no additional execution privileges needed. User interaction is not needed for e
nvd
CVE-2025-20721P3HIGHCVSS 7.8v13.0v14.0+2 more2025-10-14
CVE-2025-20721 [HIGH] CWE-787 CVE-2025-20721: In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead
In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10089545; Issue ID: MSV-4279.
nvd
CVE-2024-22012P3HIGHCVSS 7.8vAndroid kernel2024-02-07
CVE-2024-22012 [HIGH] CWE-787 CVE-2024-22012: there is a possible out of bounds write due to a missing bounds check. This could lead to local esca
there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21235P3HIGHCVSS 7.8v11.0v13.0+2 more2023-08-14
CVE-2023-21235 [HIGH] CVE-2023-21235: In onCreate of LockSettingsActivity.java, there is a possible way set a new lockscreen PIN without e
In onCreate of LockSettingsActivity.java, there is a possible way set a new lockscreen PIN without entering the existing PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34734P3HIGHCVSS 7.8v13.0v14.0+2 more2024-08-15
CVE-2024-34734 [HIGH] CWE-1188 CVE-2024-34734: In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable
In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21126P3HIGHCVSS 7.8v13.0vAndroid-132023-06-15
CVE-2023-21126 [HIGH] CWE-276 CVE-2023-21126: In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitr
In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-271846393
nvd
CVE-2024-34736P3HIGHCVSS 7.8v12.0v12.1+6 more2024-08-15
CVE-2024-34736 [HIGH] CVE-2024-34736: In setupVideoEncoder of StagefrightRecorder.cpp, there is a possible asynchronous playback when B-fr
In setupVideoEncoder of StagefrightRecorder.cpp, there is a possible asynchronous playback when B-frame support is enabled. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40106P3HIGHCVSS 7.8v11.0v12.0+8 more2024-02-15
CVE-2023-40106 [HIGH] CWE-269 CVE-2023-40106: In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity fro
In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20768P3HIGHCVSS 7.8v14.0v15.0+1 more2025-12-02
CVE-2025-20768 [HIGH] CWE-125 CVE-2025-20768: In display, there is a possible out of bounds read due to a missing bounds check. This could lead to
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4805.
nvd