Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 70 of 339
CVE-2023-48402P3HIGHCVSS 7.8vAndroid kernel2023-12-08
CVE-2023-48402 [HIGH] CWE-862 CVE-2023-48402: In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could le
In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-42740P3HIGHCVSS 7.8v11.0v12.0+1 more2023-12-04
CVE-2023-42740 [HIGH] CWE-862 CVE-2023-42740: In telecom service, there is a possible way to write permission usage records of an app due to a mis
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-42746P3HIGHCVSS 7.8v11.0v12.0+1 more2023-12-04
CVE-2023-42746 [HIGH] CWE-862 CVE-2023-42746: In power manager, there is a possible missing permission check. This could lead to local escalation
In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-42739P3HIGHCVSS 7.8v11.0v12.0+1 more2023-12-04
CVE-2023-42739 [HIGH] CWE-862 CVE-2023-42739: In engineermode service, there is a possible way to write permission usage records of an app due to
In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-35676P3HIGHCVSS 7.8v12.0v12.1+4 more2023-09-11
CVE-2023-35676 [HIGH] CWE-269 CVE-2023-35676: In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a ba
In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35682P3HIGHCVSS 7.8v11.0v12.0+6 more2023-09-11
CVE-2023-35682 [HIGH] CVE-2023-35682: In hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary
In hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary components due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-35665P3HIGHCVSS 7.8v11.0v12.0+6 more2023-09-11
CVE-2023-35665 [HIGH] CWE-862 CVE-2023-35665: In multiple files, there is a possible way to import a contact from another user due to a missing pe
In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35670P3HIGHCVSS 7.8v11.0v12.0+6 more2023-09-11
CVE-2023-35670 [HIGH] CWE-22 CVE-2023-35670: In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' e
In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21254P3HIGHCVSS 7.8v13.0v132023-07-13
CVE-2023-21254 [HIGH] CWE-863 CVE-2023-21254: In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time pe
In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21192P3HIGHCVSS 7.8v13.0vAndroid-132023-06-28
CVE-2023-21192 [HIGH] CWE-20 CVE-2023-21192: In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to s
In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods that are not enabled due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1
nvd
CVE-2023-21081P3HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21081 [HIGH] CVE-2023-21081: In multiple functions of PackageInstallerService.java and related files, there is a possible way to
In multiple functions of PackageInstallerService.java and related files, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11
nvd
CVE-2024-20015P3HIGHCVSS 7.8v12.0v13.0+1 more2024-02-05
CVE-2024-20015 [HIGH] CWE-305 CVE-2024-20015: In telephony, there is a possible escalation of privilege due to a permissions bypass. This could le
In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441419; Issue ID: ALPS08441419.
nvd
CVE-2023-21100P3HIGHCVSS 7.8v12.0v12.1+2 more2023-04-19
CVE-2023-21100 [HIGH] CWE-787 CVE-2023-21100: In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This
In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-242544249
nvd
CVE-2023-20985P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-20985 [HIGH] CWE-787 CVE-2023-20985: In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due
In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245915315
nvd
CVE-2023-21022P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21022 [HIGH] CWE-787 CVE-2023-21022: In BufferBlock of Suballocation.cpp, there is a possible out of bounds write due to memory corruptio
In BufferBlock of Suballocation.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-236098131
nvd
CVE-2023-20936P3HIGHCVSS 7.8v11.0v12.0+3 more2023-03-24
CVE-2023-20936 [HIGH] CWE-787 CVE-2023-20936: In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bo
In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-226927612
nvd
CVE-2023-21372P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21372 [HIGH] CWE-125 CVE-2023-21372: In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead
In libdexfile, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21245P3HIGHCVSS 7.8v11.0v12.0+6 more2023-07-13
CVE-2023-21245 [HIGH] CWE-863 CVE-2023-21245: In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible w
In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during device setup due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20975P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-20975 [HIGH] CWE-863 CVE-2023-20975: In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way t
In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible way to bypass DISALLOW_CONTENT_CAPTURE due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android I
nvd
CVE-2025-20668P3HIGHCVSS 7.8v14.0v15.02025-05-05
CVE-2025-20668 [HIGH] CWE-787 CVE-2025-20668: In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09625562; Issue ID: MSV-3027.
nvd