Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 60 of 339
CVE-2024-40650P3HIGHCVSS 7.8v12.0v12.1+6 more2024-09-11
CVE-2024-40650 [HIGH] CWE-862 CVE-2024-40650: In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FR
In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20797P3HIGHCVSS 7.8v14.0v15.0+1 more2026-01-06
CVE-2025-20797 [HIGH] CWE-121 CVE-2025-20797: In battery, there is a possible out of bounds write due to a missing bounds check. This could lead t
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5534.
nvd
CVE-2025-20798P3HIGHCVSS 7.8v14.0v15.0+1 more2026-01-06
CVE-2025-20798 [HIGH] CWE-787 CVE-2025-20798: In battery, there is a possible out of bounds write due to a missing bounds check. This could lead t
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5533.
nvd
CVE-2017-13316P3HIGHCVSS 7.8v6.0v6.0.1+8 more2024-11-27
CVE-2017-13316 [HIGH] CWE-862 CVE-2017-13316: In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a miss
In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-40657P3HIGHCVSS 7.8v12.0v12.1+6 more2024-09-11
CVE-2024-40657 [HIGH] CWE-269 CVE-2024-40657: In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable app
In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32919P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-32919 [HIGH] CWE-843 CVE-2024-32919: In lwis_add_completion_fence of lwis_fence.c, there is a possible escalation of privilege due to typ
In lwis_add_completion_fence of lwis_fence.c, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20763P3HIGHCVSS 7.8v14.0v15.0+1 more2025-12-02
CVE-2025-20763 [HIGH] CWE-787 CVE-2025-20763: In mmdvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to
In mmdvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10267218; Issue ID: MSV-5032.
nvd
CVE-2025-20764P3HIGHCVSS 7.8v14.0v15.0+1 more2025-12-02
CVE-2025-20764 [HIGH] CWE-787 CVE-2025-20764: In smi, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In smi, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10259774; Issue ID: MSV-5029.
nvd
CVE-2024-34730P3HIGHCVSS 7.8v12.0v12.1+6 more2025-01-21
CVE-2024-34730 [HIGH] CWE-276 CVE-2024-34730: In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due
In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9382P3HIGHCVSS 7.8v6.0v6.0.1+4 more2025-01-17
CVE-2018-9382 [HIGH] CWE-862 CVE-2018-9382: In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot fro
In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20795P3HIGHCVSS 7.8v13.0v14.0+2 more2026-01-06
CVE-2025-20795 [HIGH] CWE-787 CVE-2025-20795: In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lea
In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10276761; Issue ID: MSV-5141.
nvd
CVE-2024-11624P3HIGHCVSS 7.8vAndroid kernel2025-01-03
CVE-2024-11624 [HIGH] CWE-276 CVE-2024-11624: there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to loca
there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47041P3HIGHCVSS 7.8vAndroid kernel2024-10-25
CVE-2024-47041 [HIGH] CWE-125 CVE-2024-47041: In valid_address of syscall.c, there is a possible out of bounds read due to an incorrect bounds che
In valid_address of syscall.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-44093P3HIGHCVSS 7.8vAndroid kernel2024-09-13
CVE-2024-44093 [HIGH] CWE-787 CVE-2024-44093: In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic err
In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-44095P3HIGHCVSS 7.8vAndroid kernel2024-09-13
CVE-2024-44095 [HIGH] CWE-787 CVE-2024-44095: In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error
In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22418P3HIGHCVSS 7.8v13.0v14.0+2 more2025-09-02
CVE-2025-22418 [HIGH] CWE-441 CVE-2025-22418: In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead t
In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47033P3HIGHCVSS 7.8vAndroid kernel2024-10-25
CVE-2024-47033 [HIGH] CWE-416 CVE-2024-47033: In lwis_allocator_free of lwis_allocator.c, there is a possible memory corruption due to a use after
In lwis_allocator_free of lwis_allocator.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20778P3HIGHCVSS 7.8v14.0v15.0+1 more2026-01-06
CVE-2025-20778 [HIGH] CWE-787 CVE-2025-20778: In display, there is a possible out of bounds write due to a missing bounds check. This could lead t
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184870; Issue ID: MSV-4729.
nvd
CVE-2018-9344P3HIGHCVSS 7.8v8.12024-11-19
CVE-2018-9344 [HIGH] CWE-667 CVE-2018-9344: In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper lock
In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49732P3HIGHCVSS 7.8v15.0v152025-01-21
CVE-2024-49732 [HIGH] CWE-276 CVE-2024-49732: In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permis
In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd