Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 72 of 339
CVE-2023-20655P3HIGHCVSS 7.8v10.0v11.0+2 more2023-04-06
CVE-2023-20655 [HIGH] CWE-269 CVE-2023-20655: In mmsdk, there is a possible escalation of privilege due to a parcel format mismatch. This could le
In mmsdk, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203022; Issue ID: ALPS07203022.
nvd
CVE-2023-40107P3HIGHCVSS 7.8v12.0v12.1+6 more2024-02-15
CVE-2023-40107 [HIGH] CWE-416 CVE-2023-40107: In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This
In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21313P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21313 [HIGH] CWE-862 CVE-2023-21313: In Core, there is a possible way to forward calls without user knowledge due to a missing permission
In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21373P3HIGHCVSS 7.8v14.0v142023-10-30
CVE-2023-21373 [HIGH] CWE-862 CVE-2023-21373: In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing
In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2018-9428P3HIGHCVSS 7.8v8.12024-11-19
CVE-2018-9428 [HIGH] CWE-416 CVE-2018-9428: In startDevice of AAudioServiceStreamBase.cpp there is a possible out of bounds write due to a use a
In startDevice of AAudioServiceStreamBase.cpp there is a possible out of bounds write due to a use after free. This could lead to local arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation. https://source.android.com/security/bulletin/2018-07-01
nvd
CVE-2024-20092P3HIGHCVSS 7.8v12.02024-10-07
CVE-2024-20092 [HIGH] CWE-787 CVE-2024-20092: In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to l
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1700.
nvd
CVE-2023-35667P3HIGHCVSS 7.8v11.0v12.0+6 more2023-09-11
CVE-2023-35667 [HIGH] CWE-269 CVE-2023-35667: In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notificat
In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-27222P3HIGHCVSS 7.8v13.0v132024-03-11
CVE-2024-27222 [HIGH] CWE-269 CVE-2024-27222: In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app
In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_PERMISSIONS Attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-39435P3HIGHCVSS 7.8v12.0v13.0+1 more2024-09-27
CVE-2024-39435 [HIGH] CVE-2024-39435: In Logmanager service, there is a possible missing verification incorrect input. This could lead to
In Logmanager service, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional execution privileges needed.
nvd
CVE-2024-29787P3HIGHCVSS 7.8vAndroid kernel2024-06-13
CVE-2024-29787 [HIGH] CWE-416 CVE-2024-29787: In lwis_process_transactions_in_queue of lwis_transaction.c, there is a possible use after free due
In lwis_process_transactions_in_queue of lwis_transaction.c, there is a possible use after free due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2020-0176P3HIGHCVSS 7.5v10.0vAndroid-102020-06-11
CVE-2020-0176 [HIGH] CWE-20 CVE-2020-0176: In avdt_msg_prs_rej of avdt_msg.cc, there is a possible out-of-bounds read due to improper input val
In avdt_msg_prs_rej of avdt_msg.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-79702484
nvd
CVE-2023-21179P3HIGHCVSS 7.8v13.0vAndroid-132023-06-28
CVE-2023-21179 [HIGH] CVE-2023-21179: In parseSecurityParamsFromXml of XmlUtil.java, there is a possible bypass of user specified wifi enc
In parseSecurityParamsFromXml of XmlUtil.java, there is a possible bypass of user specified wifi encryption protocol due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-272755865
nvd
CVE-2024-43765P3HIGHCVSS 7.8v12.0v12.1+8 more2025-01-21
CVE-2024-43765 [HIGH] CWE-276 CVE-2024-43765: In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/over
In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2024-47016P3HIGHCVSS 7.8vAndroid kernel2024-10-25
CVE-2024-47016 [HIGH] CWE-276 CVE-2024-47016: there is a possible privilege escalation due to an insecure default value. This could lead to local
there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2024-49735P3HIGHCVSS 7.8v15.0v152025-01-21
CVE-2024-49735 [HIGH] CWE-276 CVE-2024-49735: In multiple locations, there is a possible failure to persist permissions settings due to resource e
In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-3781P3HIGHCVSS 7.8vAndroid kernel2023-10-11
CVE-2023-3781 [HIGH] CWE-667 CVE-2023-3781: there is a possible use-after-free write due to improper locking. This could lead to local escalatio
there is a possible use-after-free write due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-20939P3HIGHCVSS 7.8v12.0v12.1+2 more2023-02-28
CVE-2023-20939 [HIGH] CWE-667 CVE-2023-20939: In multiple functions of looper_backed_event_loop.cpp, there is a possible way to corrupt memory due
In multiple functions of looper_backed_event_loop.cpp, there is a possible way to corrupt memory due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-243362981
nvd
CVE-2016-2416P3CRITICALCVSS 9.8v4.0v4.0.1+20 more2016-04-18
CVE-2016-2416 [CRITICAL] CWE-264 CVE-2016-2416: libs/gui/BufferQueueConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1
libs/gui/BufferQueueConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for the android.permission.DUMP permission, which allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via a dump request, as demonstra
nvd
CVE-2019-9432P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9432 [HIGH] CWE-20 CVE-2019-9432: In Bluetooth, there is a possible out of bounds read due to improper input validation. This could le
In Bluetooth, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80546108
nvd
CVE-2021-0555P3HIGHCVSS 7.5v11.0vAndroid-112021-06-22
CVE-2021-0555 [HIGH] CWE-476 CVE-2021-0555: In RenderStruct of protostream_objectsource.cc, there is a possible crash due to a missing null chec
In RenderStruct of protostream_objectsource.cc, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179161711
nvd