Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 75 of 339
CVE-2025-48621P3HIGHCVSS 7.3v13.0v14.0+6 more2025-12-08
CVE-2025-48621 [HIGH] CWE-1188 CVE-2025-48621: In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a ins
In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2024-29757P3HIGHCVSS 7.3vAndroid kernel2024-04-05
CVE-2024-29757 [HIGH] CWE-287 CVE-2024-29757: there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local
there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-36907P3HIGHCVSS 7.3vAndroid kernel2025-09-04
CVE-2025-36907 [HIGH] CWE-122 CVE-2025-36907: In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due
In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege via USB fastboot, after a bootloader unlock, with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-48532P3HIGHCVSS 7.3v16.0v162025-09-04
CVE-2025-48532 [HIGH] CWE-441 CVE-2025-48532: In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_S
In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2016-0834P3HIGHCVSS 8.4v6.0v6.0.12016-04-18
CVE-2016-0834 [HIGH] CWE-20 CVE-2016-0834: An unspecified media codec in mediaserver in Android 6.x before 2016-04-01 allows remote attackers t
An unspecified media codec in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26220548.
nvd
CVE-2017-0784P3HIGHCVSS 8.8v5.0v5.0.1+10 more2017-09-08
CVE-2017-0784 [HIGH] CWE-732 CVE-2017-0784: A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.
A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37287958.
nvd
CVE-2021-22492P3HIGHCVSS 8.8v8.0v8.1+2 more2021-01-05
CVE-2021-22492 [HIGH] CWE-120 CVE-2021-22492: An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Broadcom Bluetoo
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Broadcom Bluetooth chipsets) software. The Bluetooth UART driver has a buffer overflow. The Samsung ID is SVE-2020-18731 (January 2021).
nvd
CVE-2016-2463P3HIGHCVSS 8.4v4.0v4.0.1+20 more2016-06-13
CVE-2016-2463 [HIGH] CWE-119 CVE-2016-2463: Multiple integer overflows in the h264dec component in libstagefright in mediaserver in Android 4.x
Multiple integer overflows in the h264dec component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file that triggers a large memory allocation, aka internal
nvd
CVE-2016-2508P3HIGHCVSS 7.8v4.0v4.0.1+20 more2016-07-11
CVE-2016-2508 [HIGH] CWE-119 CVE-2016-2508: media/libmediaplayerservice/nuplayer/GenericSource.cpp in mediaserver in Android 4.x before 4.4.4, 5
media/libmediaplayerservice/nuplayer/GenericSource.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate certain track data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 2879
nvd
CVE-2017-0810P3HIGHCVSS 7.8v6.0v6.0.1+5 more2017-10-04
CVE-2017-0810 [HIGH] CWE-119 CVE-2017-0810: A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. V
A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38207066.
nvd
CVE-2017-0811P3HIGHCVSS 7.8v5.0v5.0.1+11 more2017-10-04
CVE-2017-0811 [HIGH] CVE-2017-0811: A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Ve
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37930177.
nvd
CVE-2016-3862P3HIGHCVSS 7.8v4.0v4.0.1+20 more2016-09-11
CVE-2016-3862 [HIGH] CWE-119 CVE-2016-3862: media/ExifInterface.java in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x befor
media/ExifInterface.java in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 does not properly interact with the use of static variables in libjhead_jni, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal
nvd
CVE-2017-0809P3HIGHCVSS 7.8v4.0v4.0.1+28 more2017-10-04
CVE-2017-0809 [HIGH] CWE-119 CVE-2017-0809: A remote code execution vulnerability in the Android media framework (libstagefright). Product: Andr
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62673128.
nvd
CVE-2017-0637P3HIGHCVSS 7.8v5.0.2v5.1.1+5 more2017-06-14
CVE-2017-0637 [HIGH] CWE-119 CVE-2017-0637: A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a spe
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process.Product: Android. Versions: 5.0.2, 5.1.1, 6
nvd
CVE-2017-0471P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-03-08
CVE-2017-0471 [HIGH] CWE-119 CVE-2017-0471: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0469P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-03-08
CVE-2017-0469 [HIGH] CWE-119 CVE-2017-0469: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0466P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-03-08
CVE-2017-0466 [HIGH] CWE-119 CVE-2017-0466: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0468P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-03-08
CVE-2017-0468 [HIGH] CWE-119 CVE-2017-0468: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0473P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-03-08
CVE-2017-0473 [HIGH] CWE-119 CVE-2017-0473: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd
CVE-2017-0472P3HIGHCVSS 7.8v6.0v6.0.1+3 more2017-03-08
CVE-2017-0472 [HIGH] CWE-119 CVE-2017-0472: A remote code execution vulnerability in Mediaserver could enable an attacker using a specially craf
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. A
nvd