Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 61 of 339
CVE-2024-49742P3HIGHCVSS 7.8v12.0v12.1+8 more2025-01-21
CVE-2024-49742 [HIGH] CWE-269 CVE-2024-49742: In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-20796P3HIGHCVSS 7.8v15.02026-01-06
CVE-2025-20796 [HIGH] CWE-1285 CVE-2025-20796: In imgsys, there is a possible out of bounds write due to improper input validation. This could lead
In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10314745; Issue ID: MSV-5553.
nvd
CVE-2025-20800P3HIGHCVSS 7.8v14.0v15.0+1 more2026-01-06
CVE-2025-20800 [HIGH] CWE-787 CVE-2025-20800: In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead t
In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10267349; Issue ID: MSV-5033.
nvd
CVE-2024-29779P3HIGHCVSS 7.8vAndroid kernel2024-09-13
CVE-2024-29779 [HIGH] CWE-269 CVE-2024-29779: there is a possible escalation of privilege due to an unusual root cause. This could lead to local e
there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21399P3HIGHCVSS 7.8vAndroid kernel2023-07-13
CVE-2023-21399 [HIGH] CWE-327 CVE-2023-21399: there is a possible way to bypass cryptographic assurances due to a logic error in the code. This co
there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-0517P3HIGHCVSS 7.5v11.0vAndroid-112021-06-21
CVE-2021-0517 [HIGH] CWE-670 CVE-2021-0517: In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state deter
In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determination due to a logic error in the code. This could lead to biasing of networking tasks to occur on non-VPN networks, which could lead to remote information disclosure, with no additional execution privileges needed. User interaction is not needed for e
nvd
CVE-2015-6617P3CRITICALCVSS 9.3≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-6617 [CRITICAL] CWE-119 CVE-2015-6617: Skia, as used in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01, allows remote attackers to e
Skia, as used in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23648740.
nvd
CVE-2022-20516P3HIGHCVSS 7.5v13.0vAndroid-132022-12-16
CVE-2022-20516 [HIGH] CWE-191 CVE-2022-20516: In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an i
In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224002331
nvd
CVE-2019-9281P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9281 [HIGH] CWE-22 CVE-2019-9281: In GoogleContactsSyncAdapter, there is a possible path traversal due to improper input sanitization.
In GoogleContactsSyncAdapter, there is a possible path traversal due to improper input sanitization. This could lead to a bypass of user interaction requirements with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-32748076
nvd
CVE-2021-39762P3HIGHCVSS 7.5v12.1vAndroid-12L2022-03-30
CVE-2021-39762 [HIGH] CWE-190 CVE-2021-39762: In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to re
In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-210625816
nvd
CVE-2021-39809P3HIGHCVSS 7.5v10.0v11.0+3 more2022-04-12
CVE-2021-39809 [HIGH] CWE-125 CVE-2021-39809: In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a mis
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-20583
nvd
CVE-2022-20545P3HIGHCVSS 7.5v13.0vAndroid-132022-12-16
CVE-2022-20545 [HIGH] CWE-20 CVE-2022-20545: In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to
In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-239368697
nvd
CVE-2024-27211P3HIGHCVSS 7.7v13.0v132024-03-11
CVE-2024-27211 [HIGH] CWE-787 CVE-2024-27211: In AtiHandleAPOMsgType of ati_Main.c, there is a possible OOB write due to a missing null check. Thi
In AtiHandleAPOMsgType of ati_Main.c, there is a possible OOB write due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2015-8507P3CRITICALCVSS 9.3v6.02015-12-08
CVE-2015-8507 [CRITICAL] CVE-2015-8507: mediaserver in Android 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or ca
mediaserver in Android 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24157524, a different vulnerability than CVE-2015-6616, CVE-2015-8505, and CVE-2015-8506.
nvd
CVE-2015-8506P3CRITICALCVSS 9.3≥ 5.0, < 5.1.1v6.02015-12-08
CVE-2015-8506 [CRITICAL] CVE-2015-8506: mediaserver in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to exec
mediaserver in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24441553, a different vulnerability than CVE-2015-6616, CVE-2015-8505, and CVE-2015-8507.
nvd
CVE-2022-20247P3HIGHCVSS 7.5v13.0.0vAndroid-132022-08-11
CVE-2022-20247 [HIGH] CWE-787 CVE-2022-20247: In Media, there is a possible out of bounds read due to a heap buffer overflow. This could lead to r
In Media, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-229858836
nvd
CVE-2023-21027P3HIGHCVSS 7.5v13.0vAndroid-132023-03-24
CVE-2023-21027 [HIGH] CWE-287 CVE-2023-21027: In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration
In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-216854451
nvd
CVE-2023-21201P3HIGHCVSS 7.5v13.0vAndroid-132023-06-28
CVE-2023-21201 [HIGH] CWE-125 CVE-2023-21201: In on_create_record_event of btif_sdp_server.cc, there is a possible out of bounds read due to a mis
In on_create_record_event of btif_sdp_server.cc, there is a possible out of bounds read due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-263545186
nvd
CVE-2022-20418P3HIGHCVSS 7.5v12.0v12.1+2 more2022-10-11
CVE-2022-20418 [HIGH] CWE-125 CVE-2022-20418: In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds
In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-231986464
nvd
CVE-2023-21193P3HIGHCVSS 7.5v13.0vAndroid-132023-06-28
CVE-2023-21193 [HIGH] CWE-190 CVE-2023-21193: In VideoFrame of VideoFrame.h, there is a possible abort due to an integer overflow. This could lead
In VideoFrame of VideoFrame.h, there is a possible abort due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-233006499
nvd