Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 59 of 339
CVE-2024-43095P3HIGHCVSS 7.8v12.0v12.1+8 more2025-01-21
CVE-2024-43095 [HIGH] CWE-203 CVE-2024-43095: In multiple locations, there is a possible way to obtain any system permission due to a logic error
In multiple locations, there is a possible way to obtain any system permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2018-9374P3HIGHCVSS 7.8v6.0v6.0.1+8 more2024-11-28
CVE-2018-9374 [HIGH] CWE-863 CVE-2018-9374: In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This coul
In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21269P3HIGHCVSS 7.8v13.0v132023-08-14
CVE-2023-21269 [HIGH] CWE-269 CVE-2023-21269: In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into Pi
In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21117P3HIGHCVSS 7.8v13.0vAndroid-132023-05-15
CVE-2023-21117 [HIGH] CWE-863 CVE-2023-21117: In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated
In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to register a broadcast receiver due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13A
nvd
CVE-2023-40132P3HIGHCVSS 7.8v12.0v12.1+3 more2025-01-21
CVE-2023-40132 [HIGH] CWE-276 CVE-2023-40132: In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content pr
In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-35692P3HIGHCVSS 7.8vAndroid kernel2023-07-14
CVE-2023-35692 [HIGH] CWE-273 CVE-2023-35692: In getLocationCache of GeoLocation.java, there is a possible way to send a mock location during an e
In getLocationCache of GeoLocation.java, there is a possible way to send a mock location during an emergency call due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21139P3HIGHCVSS 7.8v13.0vAndroid-132023-06-15
CVE-2023-21139 [HIGH] CWE-276 CVE-2023-21139: In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due
In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-271845008
nvd
CVE-2022-20131P3HIGHCVSS 7.5v10.0v11.0+3 more2022-06-15
CVE-2022-20131 [HIGH] CWE-125 CVE-2022-20131: In nci_proc_rf_management_ntf of nci_hrcv.cc, there is a possible out of bounds read due to a missin
In nci_proc_rf_management_ntf of nci_hrcv.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-22185666
nvd
CVE-2018-9431P3HIGHCVSS 7.8v8.0v8.1+1 more2024-12-02
CVE-2018-9431 [HIGH] CWE-276 CVE-2018-9431: In OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input valida
In OSUInfo of OSUInfo.java, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21270P3HIGHCVSS 7.8v12.0v12.1+1 more2024-11-19
CVE-2023-21270 [HIGH] CWE-863 CVE-2023-21270: In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app t
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32927P3HIGHCVSS 7.8vAndroid kernel2024-08-19
CVE-2024-32927 [HIGH] CWE-416 CVE-2024-32927: In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking.
In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34743P3HIGHCVSS 7.8v14.0v142024-08-15
CVE-2024-34743 [HIGH] CWE-1021 CVE-2024-34743: In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a
In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-34738P3HIGHCVSS 7.8v13.0v14.0+2 more2024-08-15
CVE-2024-34738 [HIGH] CWE-266 CVE-2024-34738: In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read t
In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-43769P3HIGHCVSS 7.8v13.0v14.0+4 more2025-01-03
CVE-2024-43769 [HIGH] CWE-276 CVE-2024-43769: In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could pre
In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47017P3HIGHCVSS 7.8vAndroid kernel2024-10-25
CVE-2024-47017 [HIGH] CWE-416 CVE-2024-47017: In ufshc_scsi_cmd of ufs.c, there is a possible stack variable use after free due to a use after fre
In ufshc_scsi_cmd of ufs.c, there is a possible stack variable use after free due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27233P3HIGHCVSS 7.8v13.0v132024-03-11
CVE-2024-27233 [HIGH] CWE-269 CVE-2024-27233: In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data.
In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49738P3HIGHCVSS 7.8v12.0v12.1+8 more2025-01-21
CVE-2024-49738 [HIGH] CWE-787 CVE-2024-49738: In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local esc
In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49745P3HIGHCVSS 7.8v12.0v12.1+8 more2025-01-21
CVE-2024-49745 [HIGH] CWE-787 CVE-2024-49745: In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check.
In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9417P3HIGHCVSS 7.8vKernel2024-11-19
CVE-2018-9417 [HIGH] CWE-416 CVE-2018-9417: In f_hidg_read and hidg_disable of f_hid.c, there is a possible use-after-free due to improper locki
In f_hidg_read and hidg_disable of f_hid.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-44092P3HIGHCVSS 7.8vAndroid kernel2024-09-13
CVE-2024-44092 [HIGH] CWE-489 CVE-2024-44092: There is a possible LCS signing enforcement missing due to test/debugging code left in a production
There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd