Google Android vulnerabilities
9,646 known vulnerabilities affecting google/android.
Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2
Vulnerabilities
Page 63 of 483
CVE-2024-23713HIGHCVSS 7.8v12.0v12.1+6 more2024-05-07
CVE-2024-23713 [HIGH] CWE-269 CVE-2024-23713: In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to pers
In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-0024HIGHCVSS 7.8v12.0v12.1+6 more2024-05-07
CVE-2024-0024 [HIGH] CWE-269 CVE-2024-0024: In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce us
In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvdandroid
CVE-2024-23708HIGHCVSS 7.8v12.0v12.1+6 more2024-05-07
CVE-2024-23708 [HIGH] CWE-451 CVE-2024-23708: In multiple functions of NotificationManagerService.java, there is a possible way to not show a toas
In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-0043HIGHCVSS 7.8v12.0v12.1+6 more2024-05-07
CVE-2024-0043 [HIGH] CWE-863 CVE-2024-0043: In multiple locations, there is a possible notification listener grant to an app running in the work
In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvdandroid
CVE-2024-0042HIGHCVSS 7.8vAndroid SoC2024-05-07
CVE-2024-0042 [HIGH] CWE-295 CVE-2024-0042: In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used cryp
In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DRM content protection with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-0025HIGHCVSS 7.8v12.0v12.1+6 more2024-05-07
CVE-2024-0025 [HIGH] CWE-284 CVE-2024-0025: In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch d
In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-23705HIGHCVSS 7.8v12.0v12.1+6 more2024-05-07
CVE-2024-23705 [HIGH] CWE-20 CVE-2024-23705: In multiple locations, there is a possible failure to persist or enforce user restrictions due to im
In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvdandroid
CVE-2024-23704HIGHCVSS 7.8v13.0v14.0+2 more2024-05-07
CVE-2024-23704 [HIGH] CWE-862 CVE-2024-23704: In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONF
In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-0022MEDIUMCVSS 5.5v13.0v14.0+2 more2024-05-07
CVE-2024-0022 [MEDIUM] CWE-20 CVE-2024-0022: In multiple functions of CompanionDeviceManagerService.java, there is a possible launch Notification
In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-23709MEDIUMCVSS 6.5v12.0v12.1+6 more2024-05-07
CVE-2024-23709 [MEDIUM] CWE-787 CVE-2024-23709: In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This c
In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
nvdandroid
CVE-2024-0027MEDIUMCVSS 5.5v12.0v12.1+6 more2024-05-07
CVE-2024-0027 [MEDIUM] CWE-770 CVE-2024-0027: In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to reso
In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-0026MEDIUMCVSS 5.5v12.0v12.1+6 more2024-05-07
CVE-2024-0026 [MEDIUM] CWE-770 CVE-2024-0026: In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to
In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-23712MEDIUMCVSS 5.5v12.0v12.1+6 more2024-05-07
CVE-2024-23712 [MEDIUM] CWE-400 CVE-2024-23712: In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /dat
In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_accesses.xml due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2024-20057HIGHCVSS 7.2v12.0v13.0+1 more2024-05-06
CVE-2024-20057 [HIGH] CWE-787 CVE-2024-20057: In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lea
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ID: ALPS08587881.
nvdandroid
CVE-2024-20064HIGHCVSS 7.8v13.0v14.02024-05-06
CVE-2024-20064 [HIGH] CWE-20 CVE-2024-20064: In wlan service, there is a possible out of bounds write due to improper input validation. This coul
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08572601; Issue ID: MSV-1229.
nvd
CVE-2024-20021MEDIUMCVSS 6.7v12.0v13.0+1 more2024-05-06
CVE-2024-20021 [MEDIUM] CWE-269 CVE-2024-20021: In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error.
In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08584568; Issue ID: MSV-1249.
nvd
CVE-2023-32871MEDIUMCVSS 5.3v12.0v13.0+2 more2024-05-06
CVE-2023-32871 [MEDIUM] CWE-391 CVE-2023-32871: In DA, there is a possible permission bypass due to an incorrect status check. This could lead to lo
In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514.
nvdandroid
CVE-2024-20056MEDIUMCVSS 6.7v12.0v13.0+1 more2024-05-06
CVE-2024-20056 [MEDIUM] CWE-20 CVE-2024-20056: In preloader, there is a possible escalation of privilege due to an insecure default value. This cou
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185.
nvdandroid
CVE-2023-32873MEDIUMCVSS 6.7v12.0v13.0+1 more2024-05-06
CVE-2023-32873 [MEDIUM] CWE-787 CVE-2023-32873: In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lea
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08583919; Issue ID: ALPS08304227.
nvdandroid
CVE-2024-20058MEDIUMCVSS 4.4v12.0v13.0+1 more2024-05-06
CVE-2024-20058 [MEDIUM] CWE-125 CVE-2024-20058: In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead
In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580204; Issue ID: ALPS08580204.
nvd