Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 7 of 339
CVE-2020-0380P2CRITICALCVSS 9.8v8.0v8.1+4 more2020-09-17
CVE-2020-0380 [CRITICAL] CWE-787 CVE-2020-0380: In allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds
In allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-146398979
nvd
CVE-2017-13282P3CRITICALCVSS 9.8v7.0v7.1.1+3 more2018-04-04
CVE-2017-13282 [CRITICAL] CWE-119 CVE-2017-13282: In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible stack buffer overflow due to a
In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71603315.
nvd
CVE-2023-35646P2CRITICALCVSS 9.8vAndroid kernel2023-10-11
CVE-2023-35646 [CRITICAL] CWE-787 CVE-2023-35646: In TBD of TBD, there is a possible stack buffer overflow due to a missing bounds check. This could l
In TBD of TBD, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35662P2CRITICALCVSS 9.8vAndroid kernel2023-10-11
CVE-2023-35662 [CRITICAL] CWE-787 CVE-2023-35662: there is a possible out of bounds write due to buffer overflow. This could lead to remote code execu
there is a possible out of bounds write due to buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-48626P2CRITICALCVSS 9.8v13.0v14.0+6 more2025-12-08
CVE-2025-48626 [CRITICAL] CWE-693 CVE-2025-48626: In multiple locations, there is a possible way to launch an application from the background due to a
In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2016-5348P3MEDIUMCVSS 5.9PoCv4.0v4.0.1+21 more2016-10-10
CVE-2016-5348 [MEDIUM] CWE-399 CVE-2016-5348: The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 20
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-the-middle attackers to cause a denial of service (memory consumption, and device hang or reboot) via a large xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka in
nvd
CVE-2025-26438P3HIGHCVSS 8.8v13.0v14.0+4 more2025-09-04
CVE-2025-26438 [HIGH] CWE-287 CVE-2025-26438: In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authe
In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-32318P3HIGHCVSS 8.8v16.0v162025-09-05
CVE-2025-32318 [HIGH] CWE-122 CVE-2025-32318: In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to r
In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9356P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-11-06
CVE-2018-9356 [CRITICAL] CWE-415 CVE-2018-9356: In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. Thi
In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1
nvd
CVE-2018-9355P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-11-06
CVE-2018-9355 [CRITICAL] CWE-787 CVE-2018-9355: In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missin
In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Andr
nvd
CVE-2017-13177P3CRITICALCVSS 9.8v5.1.1v6.0+6 more2018-01-12
CVE-2017-13177 [CRITICAL] CWE-119 CVE-2017-13177: In several functions of libhevc, NEON registers are not preserved. This could lead to remote code ex
In several functions of libhevc, NEON registers are not preserved. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68320413.
nvd
CVE-2017-13178P3CRITICALCVSS 9.8v6.0v6.0.1+5 more2018-01-12
CVE-2017-13178 [CRITICAL] CWE-416 CVE-2017-13178: In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due
In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due to a use after free when buffer allocation fails. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0.1, 7.0
nvd
CVE-2017-13283P3CRITICALCVSS 9.8v7.0v7.1.1+3 more2018-04-04
CVE-2017-13283 [CRITICAL] CWE-787 CVE-2017-13283: In avrc_ctrl_pars_vendor_rsp of bluetooth avrcp_ctrl, there is a possible out of bounds write on the
In avrc_ctrl_pars_vendor_rsp of bluetooth avrcp_ctrl, there is a possible out of bounds write on the stack due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71
nvd
CVE-2017-13266P3CRITICALCVSS 9.8v5.1.1v6.0+6 more2018-04-04
CVE-2017-13266 [CRITICAL] CWE-119 CVE-2017-13266: In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bo
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69478941.
nvd
CVE-2022-26447P3CRITICALCVSS 9.8v10.0v11.0+1 more2022-09-06
CVE-2022-26447 [CRITICAL] CWE-787 CVE-2022-26447: In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could le
In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784478; Issue ID: ALPS06784478.
nvd
CVE-2026-0110P3CRITICALCVSS 9.8vAndroid kernel2026-03-10
CVE-2026-0110 [CRITICAL] CWE-120 CVE-2026-0110: In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This c
In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-20080P3CRITICALCVSS 9.8v13.0v14.02024-07-01
CVE-2024-20080 [CRITICAL] CWE-295 CVE-2024-20080: In gnss service, there is a possible escalation of privilege due to improper certificate validation.
In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.
nvd
CVE-2010-4804P3MEDIUMCVSS 4.3PoC≤ 2.3.3v1.5+6 more2011-06-09
CVE-2010-4804 [MEDIUM] CWE-200 CVE-2010-4804: The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via c
The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// URIs, related to (1) BrowserActivity.java and (2) BrowserSettings.java in com/android/browser/.
nvd
CVE-2023-40077P3HIGHCVSS 8.1v11.0v12.0+8 more2023-12-04
CVE-2023-40077 [HIGH] CWE-362 CVE-2023-40077: In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. Th
In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2017-13179P3CRITICALCVSS 9.8v6.0.1v7.0+4 more2018-01-12
CVE-2017-13179 [CRITICAL] CWE-416 CVE-2017-13179: In the ihevcd_allocate_static_bufs and ihevcd_create functions of SoftHEVC, there is a possible out-
In the ihevcd_allocate_static_bufs and ihevcd_create functions of SoftHEVC, there is a possible out-of-bounds write due to a use after free. Both ps_codec_obj and ps_create_op->s_ivd_create_op_t.pv_handle point to the same memory and ps_codec_obj could be freed without clearing ps_create_op->s_ivd_create_op_t.pv_handle. This could lead to remote c
nvd