cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 60 of 339
CVE-2024-40650P3HIGHCVSS 7.8v12.0v12.1+6 more2024-09-11
CVE-2024-40650 [HIGH] CWE-862 CVE-2024-40650: In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FR In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20797P3HIGHCVSS 7.8v14.0v15.0+1 more2026-01-06
CVE-2025-20797 [HIGH] CWE-121 CVE-2025-20797: In battery, there is a possible out of bounds write due to a missing bounds check. This could lead t In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5534.
nvd
CVE-2025-20798P3HIGHCVSS 7.8v14.0v15.0+1 more2026-01-06
CVE-2025-20798 [HIGH] CWE-787 CVE-2025-20798: In battery, there is a possible out of bounds write due to a missing bounds check. This could lead t In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5533.
nvd
CVE-2017-13316P3HIGHCVSS 7.8v6.0v6.0.1+8 more2024-11-27
CVE-2017-13316 [HIGH] CWE-862 CVE-2017-13316: In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a miss In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-40657P3HIGHCVSS 7.8v12.0v12.1+6 more2024-09-11
CVE-2024-40657 [HIGH] CWE-269 CVE-2024-40657: In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable app In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-32919P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-32919 [HIGH] CWE-843 CVE-2024-32919: In lwis_add_completion_fence of lwis_fence.c, there is a possible escalation of privilege due to typ In lwis_add_completion_fence of lwis_fence.c, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20763P3HIGHCVSS 7.8v14.0v15.0+1 more2025-12-02
CVE-2025-20763 [HIGH] CWE-787 CVE-2025-20763: In mmdvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to In mmdvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10267218; Issue ID: MSV-5032.
nvd
CVE-2025-20764P3HIGHCVSS 7.8v14.0v15.0+1 more2025-12-02
CVE-2025-20764 [HIGH] CWE-787 CVE-2025-20764: In smi, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In smi, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10259774; Issue ID: MSV-5029.
nvd
CVE-2024-34730P3HIGHCVSS 7.8v12.0v12.1+6 more2025-01-21
CVE-2024-34730 [HIGH] CWE-276 CVE-2024-34730: In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9382P3HIGHCVSS 7.8v6.0v6.0.1+4 more2025-01-17
CVE-2018-9382 [HIGH] CWE-862 CVE-2018-9382: In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot fro In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20795P3HIGHCVSS 7.8v13.0v14.0+2 more2026-01-06
CVE-2025-20795 [HIGH] CWE-787 CVE-2025-20795: In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lea In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10276761; Issue ID: MSV-5141.
nvd
CVE-2024-11624P3HIGHCVSS 7.8vAndroid kernel2025-01-03
CVE-2024-11624 [HIGH] CWE-276 CVE-2024-11624: there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to loca there is a possible to add apps to bypass VPN due to Undeclared Permission . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47041P3HIGHCVSS 7.8vAndroid kernel2024-10-25
CVE-2024-47041 [HIGH] CWE-125 CVE-2024-47041: In valid_address of syscall.c, there is a possible out of bounds read due to an incorrect bounds che In valid_address of syscall.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-44093P3HIGHCVSS 7.8vAndroid kernel2024-09-13
CVE-2024-44093 [HIGH] CWE-787 CVE-2024-44093: In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic err In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-44095P3HIGHCVSS 7.8vAndroid kernel2024-09-13
CVE-2024-44095 [HIGH] CWE-787 CVE-2024-44095: In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22418P3HIGHCVSS 7.8v13.0v14.0+2 more2025-09-02
CVE-2025-22418 [HIGH] CWE-441 CVE-2025-22418: In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead t In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-47033P3HIGHCVSS 7.8vAndroid kernel2024-10-25
CVE-2024-47033 [HIGH] CWE-416 CVE-2024-47033: In lwis_allocator_free of lwis_allocator.c, there is a possible memory corruption due to a use after In lwis_allocator_free of lwis_allocator.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-20778P3HIGHCVSS 7.8v14.0v15.0+1 more2026-01-06
CVE-2025-20778 [HIGH] CWE-787 CVE-2025-20778: In display, there is a possible out of bounds write due to a missing bounds check. This could lead t In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184870; Issue ID: MSV-4729.
nvd
CVE-2018-9344P3HIGHCVSS 7.8v8.12024-11-19
CVE-2018-9344 [HIGH] CWE-667 CVE-2018-9344: In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper lock In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49732P3HIGHCVSS 7.8v15.0v152025-01-21
CVE-2024-49732 [HIGH] CWE-276 CVE-2024-49732: In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permis In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
Google Android vulnerabilities | cvebase