Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 66 of 339
CVE-2021-0330P3HIGHCVSS 7.8v9.0v10.0+2 more2021-02-10
CVE-2021-0330 [HIGH] CWE-416 CVE-2021-0330: In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to imprope
In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in storaged with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-170732441
nvd
CVE-2019-2208P3HIGHCVSS 7.5v9.0vAndroid-8.1+1 more2019-11-13
CVE-2019-2208 [HIGH] CWE-125 CVE-2019-2208: In PromiseBuiltinsAssembler::NewPromiseCapability of builtins-promise.cc, there is a possible out of
In PromiseBuiltinsAssembler::NewPromiseCapability of builtins-promise.cc, there is a possible out of bounds read in v8 JIT code due to a bug in code generation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.1, Android-
nvd
CVE-2021-0705P3HIGHCVSS 7.8v10.0v11.0+1 more2021-10-22
CVE-2021-0705 [HIGH] CVE-2021-0705: In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running i
In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and keep granted permissions due to Bypass of Background Service Restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:
nvd
CVE-2021-0519P3HIGHCVSS 7.8v8.1v9.0+3 more2021-08-17
CVE-2021-0519 [HIGH] CWE-787 CVE-2021-0519: In BITSTREAM_FLUSH of ih264e_bitstream.h, there is a possible out of bounds write due to a heap buff
In BITSTREAM_FLUSH of ih264e_bitstream.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-176533109
nvd
CVE-2020-0074P3HIGHCVSS 7.8v8.0v8.1+4 more2020-09-17
CVE-2020-0074 [HIGH] CWE-269 CVE-2020-0074: In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass al
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 And
nvd
CVE-2022-20138P3HIGHCVSS 7.8v10.0v11.0+3 more2022-06-15
CVE-2022-20138 [HIGH] CWE-862 CVE-2022-20138: In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way fo
In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVISIONED intent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: An
nvd
CVE-2021-0925P3HIGHCVSS 7.5v12.0vAndroid-122021-12-15
CVE-2021-0925 [HIGH] CWE-125 CVE-2021-0925: In rw_t4t_sm_detect_ndef of rw_t4t.cc, there is a possible out of bounds read due to an incorrect bo
In rw_t4t_sm_detect_ndef of rw_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure due to a limited change in behavior based on the out of bounds data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andr
nvd
CVE-2023-40084P3HIGHCVSS 7.8v11.0v12.0+8 more2023-12-04
CVE-2023-40084 [HIGH] CWE-416 CVE-2023-40084: In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This co
In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-40096P3HIGHCVSS 7.8v11.0v12.0+8 more2023-12-04
CVE-2023-40096 [HIGH] CVE-2023-40096: In OpRecordAudioMonitor::onFirstRef of AudioRecordClient.cpp, there is a possible way to record audi
In OpRecordAudioMonitor::onFirstRef of AudioRecordClient.cpp, there is a possible way to record audio from the background due to a missing flag. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20955P3HIGHCVSS 7.8v11.0v12.0+3 more2023-03-24
CVE-2023-20955 [HIGH] CWE-862 CVE-2023-20955: In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin re
In onPrepareOptionsMenu of AppInfoDashboardFragment.java, there is a possible way to bypass admin restrictions and uninstall applications for all users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi
nvd
CVE-2023-20944P3HIGHCVSS 7.8v10.0v11.0+4 more2023-02-28
CVE-2023-20944 [HIGH] CWE-502 CVE-2023-20944: In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsa
In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android
nvd
CVE-2022-20520P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20520 [HIGH] CWE-1021 CVE-2022-20520: In onCreate of various files, there is a possible tapjacking/overlay attack. This could lead to loca
In onCreate of various files, there is a possible tapjacking/overlay attack. This could lead to local escalation of privilege or denial of server with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-227203202
nvd
CVE-2022-20360P3HIGHCVSS 7.8v10.0v11.0+3 more2022-08-10
CVE-2022-20360 [HIGH] CWE-862 CVE-2022-20360: In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could
In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228314987
nvd
CVE-2021-39704P3HIGHCVSS 7.8v10.0v11.0+2 more2022-03-16
CVE-2021-39704 [HIGH] CWE-281 CVE-2021-39704: In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run
In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run foreground service without user notification due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android
nvd
CVE-2023-21281P3HIGHCVSS 7.8v11.0v12.0+6 more2023-08-14
CVE-2023-21281 [HIGH] CVE-2023-21281: In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen
In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen timeout due to a logic error in the code. This could lead to local escalation of privilege across users with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20943P3HIGHCVSS 7.8v10.0v11.0+4 more2023-02-28
CVE-2023-20943 [HIGH] CWE-22 CVE-2023-20943: In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system
In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-1
nvd
CVE-2022-20220P3HIGHCVSS 7.8v12.0v12.1+1 more2022-07-13
CVE-2022-20220 [HIGH] CWE-22 CVE-2022-20220: In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal e
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-219015884
nvd
CVE-2023-21086P3HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21086 [HIGH] CVE-2023-21086: In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible
In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVers
nvd
CVE-2023-20945P3HIGHCVSS 7.8v10.0vAndroid-102023-02-28
CVE-2023-20945 [HIGH] CWE-787 CVE-2023-20945: In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write
In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-246932269
nvd
CVE-2023-20933P3HIGHCVSS 7.8v10.0v11.0+4 more2023-02-28
CVE-2023-20933 [HIGH] CWE-416 CVE-2023-20933: In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after
In several functions of MediaCodec.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-245860
nvd