Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 71 of 339
CVE-2024-25986P3HIGHCVSS 7.8v13.0v132024-03-11
CVE-2024-25986 [HIGH] CWE-119 CVE-2024-25986: In ppmp_unprotect_buf of drm_fw.c, there is a possible compromise of protected memory due to a logic
In ppmp_unprotect_buf of drm_fw.c, there is a possible compromise of protected memory due to a logic error in the code. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20934P3HIGHCVSS 7.8v12.0v12.1+2 more2023-02-28
CVE-2023-20934 [HIGH] CVE-2023-20934: In resolveAttributionSource of ServiceUtilities.cpp, there is a possible way to disable the micropho
In resolveAttributionSource of ServiceUtilities.cpp, there is a possible way to disable the microphone privacy indicator due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android
nvd
CVE-2023-40100P3HIGHCVSS 7.8v11.0v12.0+8 more2024-02-15
CVE-2023-40100 [HIGH] CWE-416 CVE-2023-40100: In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use af
In discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21110P3HIGHCVSS 7.8v11.0v12.0+3 more2023-05-15
CVE-2023-21110 [HIGH] CWE-400 CVE-2023-21110: In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A
nvd
CVE-2023-20967P3HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-20967 [HIGH] CWE-787 CVE-2023-20967: In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an in
In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-22
nvd
CVE-2023-21328P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21328 [HIGH] CWE-862 CVE-2023-21328: In Package Installer, there is a possible way to determine whether an app is installed, without quer
In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21257P3HIGHCVSS 7.8v13.0v132023-07-13
CVE-2023-21257 [HIGH] CWE-862 CVE-2023-21257: In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app
In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21128P3HIGHCVSS 7.8v11.0v12.0+3 more2023-06-15
CVE-2023-21128 [HIGH] CWE-276 CVE-2023-21128: In various functions of AppStandbyController.java, there is a possible way to break manageability sc
In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Androi
nvd
CVE-2021-0483P3HIGHCVSS 7.8v10.0v11.0+1 more2021-10-22
CVE-2021-0483 [HIGH] CWE-362 CVE-2021-0483: In multiple methods of AAudioService, there is a possible use-after-free due to a race condition. Th
In multiple methods of AAudioService, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-153358911
nvd
CVE-2025-20723P3HIGHCVSS 7.8v14.0v15.02025-10-14
CVE-2025-20723 [HIGH] CWE-787 CVE-2025-20723: In gnss driver, there is a possible out of bounds write due to an incorrect bounds check. This could
In gnss driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09920033; Issue ID: MSV-3797.
nvd
CVE-2018-9477P3HIGHCVSS 7.8v8.0v8.1+1 more2024-11-20
CVE-2018-9477 [HIGH] CWE-862 CVE-2018-9477: In the development options section of the Settings app, there is a possible authentication bypass du
In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-20443P3HIGHCVSS 7.8v13.0vAndroid-132023-06-28
CVE-2022-20443 [HIGH] CWE-1021 CVE-2022-20443: In hasInputInfo of Layer.cpp, there is a possible bypass of user interaction requirements due to a t
In hasInputInfo of Layer.cpp, there is a possible bypass of user interaction requirements due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-194480991
nvd
CVE-2023-21355P3HIGHCVSS 7.8v14.0v142023-10-30
CVE-2023-21355 [HIGH] CWE-416 CVE-2023-21355: In libaudioclient, there is a possible out of bounds write due to a use after free. This could lead
In libaudioclient, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-35689P3HIGHCVSS 7.8v11.0v13.0+2 more2023-08-14
CVE-2023-35689 [HIGH] CWE-1188 CVE-2023-35689: In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb bef
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21185P3HIGHCVSS 7.8v13.0vAndroid-132023-06-28
CVE-2023-21185 [HIGH] CWE-862 CVE-2023-21185: In multiple functions of WifiNetworkFactory.java, there is a missing permission check. This could le
In multiple functions of WifiNetworkFactory.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-266700762
nvd
CVE-2022-20450P3HIGHCVSS 7.8v10.0v11.0+4 more2022-11-08
CVE-2022-20450 [HIGH] CWE-862 CVE-2022-20450: In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass us
In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 And
nvd
CVE-2025-20979P3HIGHCVSS 7.8fixed in 15.02025-05-07
CVE-2025-20979 [HIGH] CWE-787 CVE-2025-20979: Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary co
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.
nvd
CVE-2023-21378P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21378 [HIGH] CWE-862 CVE-2023-21378: In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missi
In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21021P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21021 [HIGH] CWE-862 CVE-2023-21021: In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl.java, there is a possible way for the guest u
In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl.java, there is a possible way for the guest user to change admin user network settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andro
nvd
CVE-2023-21231P3HIGHCVSS 7.8v13.0v132023-08-14
CVE-2023-21231 [HIGH] CVE-2023-21231: In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application
In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-exported or permission-protected activity due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd