Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 63 of 339
CVE-2020-25062P3CRITICALCVSS 9.8v9.0v10.02020-08-31
CVE-2020-25062 [CRITICAL] CVE-2020-25062: An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider
An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of intended privilege restrictions. The LG ID is LVE-SMP-200017 (July 2020).
nvd
CVE-2019-20772P3CRITICALCVSS 9.8v7.0v7.1+4 more2020-04-17
CVE-2019-20772 [CRITICAL] CVE-2019-20772: An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 softwa
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Account subsystem allows authorization bypass. The LG ID is LVE-SMP-190007 (August 2019).
nvd
CVE-2020-25049P3CRITICALCVSS 9.8v9.0v10.02020-08-31
CVE-2020-25049 [CRITICAL] CVE-2020-25049: An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. StatusBarService
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. StatusBarService has insufficient DEX access control. The Samsung ID is SVE-2020-17797 (August 2020).
nvd
CVE-2020-25058P3CRITICALCVSS 9.8v8.0v8.1+2 more2020-08-31
CVE-2020-25058 [CRITICAL] CVE-2020-25058: An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The netwo
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management service does not properly restrict configuration changes. The LG ID is LVE-SMP-200012 (July 2020).
nvd
CVE-2020-12747P3CRITICALCVSS 9.8v10.02020-05-11
CVE-2020-12747 [CRITICAL] CWE-787 CVE-2020-12747: An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos980 9630 and Exynos990 9830 ch
An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos980 9630 and Exynos990 9830 chipsets) software. The Bootloader has a heap-based buffer overflow because of the mishandling of specific commands. The Samsung IDs are SVE-2020-16981, SVE-2020-16991 (May 2020).
nvd
CVE-2017-18645P3CRITICALCVSS 9.8v6.0v6.0.1+4 more2020-04-08
CVE-2017-18645 [CRITICAL] CWE-787 CVE-2017-18645: An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) (Qualcomm chipsets) softwar
An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) (Qualcomm chipsets) software. There is a panel_lpm sysfs stack-based buffer overflow. The Samsung ID is SVE-2017-9414 (December 2017).
nvd
CVE-2019-20572P3CRITICALCVSS 9.8v8.1v9.02020-03-24
CVE-2019-20572 [CRITICAL] CWE-120 CVE-2019-20572: An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (Exynos chipsets) software.
An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (Exynos chipsets) software. load_kernel has a buffer overflow via untrusted data. The Samsung ID is SVE-2019-14939 (September 2019).
nvd
CVE-2020-25282P3CRITICALCVSS 9.8v10.02020-09-11
CVE-2020-25282 [CRITICAL] CWE-862 CVE-2020-25282: An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for t
An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-200020 (September 2020).
nvd
CVE-2019-20530P3CRITICALCVSS 9.8v7.1.0v8.0+3 more2020-03-24
CVE-2019-20530 [CRITICAL] CWE-345 CVE-2019-20530: An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), P(9.0), and Q(10.0) software.
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), P(9.0), and Q(10.0) software. Arbitrary code execution is possible on the lock screen. The Samsung ID is SVE-2019-15266 (December 2019).
nvd
CVE-2024-27227P3CRITICALCVSS 9.8v132024-03-11
CVE-2024-27227 [CRITICAL] CWE-787 CVE-2024-27227: A malicious DNS response can trigger a number of OOB reads, writes, and other memory issues
A malicious DNS response can trigger a number of OOB reads, writes, and other memory issues
nvd
CVE-2015-3831P3CRITICALCVSS 9.3≤ 5.12015-10-01
CVE-2015-3831 [CRITICAL] CWE-119 CVE-2015-3831: Buffer overflow in the readAt function in BpMediaHTTPConnection in media/libmedia/IMediaHTTPConnecti
Buffer overflow in the readAt function in BpMediaHTTPConnection in media/libmedia/IMediaHTTPConnection.cpp in the mediaserver service in Android before 5.1.1 LMY48I allows attackers to execute arbitrary code via a crafted application, aka internal bug 19400722.
nvd
CVE-2015-3842P3CRITICALCVSS 9.3≤ 5.12015-10-01
CVE-2015-3842 [CRITICAL] CWE-119 CVE-2015-3842: Multiple heap-based buffer overflows in libeffects in the Audio Policy Service in mediaserver in And
Multiple heap-based buffer overflows in libeffects in the Audio Policy Service in mediaserver in Android before 5.1.1 LMY48I allow attackers to execute arbitrary code via a crafted application, aka internal bug 21953516.
nvd
CVE-2025-48577P3HIGHCVSS 7.4v14.0v15.0+4 more2026-03-02
CVE-2025-48577 [HIGH] CWE-362 CVE-2025-48577: In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a r
In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48568P3HIGHCVSS 7.4v14.0v15.0+2 more2026-03-02
CVE-2025-48568 [HIGH] CWE-362 CVE-2025-48568: In multiple locations, there is a possible lockscreen bypass due to a race condition. This could lea
In multiple locations, there is a possible lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2026-0112P3HIGHCVSS 7.4vAndroid kernel2026-03-10
CVE-2026-0112 [HIGH] CWE-362 CVE-2026-0112: In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This co
In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22441P3HIGHCVSS 7.3v13.0v14.0+4 more2025-09-04
CVE-2025-22441 [HIGH] CWE-441 CVE-2025-22441: In getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible way
In getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible way to load arbitrary java code in a privileged context due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-48594P3HIGHCVSS 7.3v14.0v15.0+4 more2025-12-08
CVE-2025-48594 [HIGH] CWE-20 CVE-2025-48594: In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion appl
In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2020-13833P3CRITICALCVSS 9.1v8.0v8.1+2 more2020-06-04
CVE-2020-13833 [CRITICAL] CWE-59 CVE-2020-13833: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The sys
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a symlink attack. The Samsung ID is SVE-2020-17183 (June 2020).
nvd
CVE-2024-40673P3MEDIUMCVSS 6.5v12.0v12.1+6 more2025-01-28
CVE-2024-40673 [MEDIUM] CWE-94 CVE-2024-40673: In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by mani
In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2019-2102P3HIGHCVSS 8.8v7.0v7.1.1+4 more2019-06-07
CVE-2019-2102 [HIGH] CWE-264 CVE-2019-2102: In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK). If
In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK). If a BLE device were to use this as a hardcoded LTK, it is theoretically possible for a proximate attacker to remotely inject keystrokes on a paired Android host due to improperly used crypto. User interaction is not needed for exploitation. Product: Androi
nvd