Google Android vulnerabilities

9,646 known vulnerabilities affecting google/android.

Total CVEs
9,646
CISA KEV
48
actively exploited
Public exploits
89
Exploited in wild
44
Severity breakdown
CRITICAL883HIGH5184MEDIUM3317LOW260UNKNOWN2

Vulnerabilities

Page 83 of 483
CVE-2023-40097HIGHCVSS 7.8v11.0v12.0+6 more2023-12-04
CVE-2023-40097 [HIGH] CWE-20 CVE-2023-40097: In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to impro In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvdandroid
CVE-2023-21227HIGHCVSS 7.5vAndroid SoC2023-12-04
CVE-2023-21227 [HIGH] CVE-2023-21227: In HTBLogKM of htbserver.c, there is a possible information disclosure due to log information disclo In HTBLogKM of htbserver.c, there is a possible information disclosure due to log information disclosure. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2023-45779HIGHCVSS 7.8vAndroid SoC2023-12-04
CVE-2023-45779 [HIGH] CVE-2023-45779: In the APEX module framework of AOSP, there is a possible malicious update to platform components du In the APEX module framework of AOSP, there is a possible malicious update to platform components due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. More details on this can be found in the referenced links.
nvdandroid
CVE-2023-42748HIGHCVSS 7.8v11.0v12.0+1 more2023-12-04
CVE-2023-42748 [HIGH] CWE-862 CVE-2023-42748: In telecom service, there is a possible missing permission check. This could lead to local escalatio In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-32850HIGHCVSS 7.8v11.0v12.02023-12-04
CVE-2023-32850 [HIGH] CWE-787 CVE-2023-32850: In decoder, there is a possible out of bounds write due to an integer overflow. This could lead to l In decoder, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08016659; Issue ID: ALPS08016659.
nvdandroid
CVE-2023-42746HIGHCVSS 7.8v11.0v12.0+1 more2023-12-04
CVE-2023-42746 [HIGH] CWE-862 CVE-2023-42746: In power manager, there is a possible missing permission check. This could lead to local escalation In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-40080HIGHCVSS 7.8v13.0v14.0+2 more2023-12-04
CVE-2023-40080 [HIGH] CWE-787 CVE-2023-40080: In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a logic erro In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2023-45777HIGHCVSS 7.8v13.0v14.0+2 more2023-12-04
CVE-2023-45777 [HIGH] CVE-2023-45777: In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to launch In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to launch arbitrary activities using system privileges due to Parcel Mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2023-42681HIGHCVSS 7.8v11.0v12.0+1 more2023-12-04
CVE-2023-42681 [HIGH] CWE-862 CVE-2023-42681: In ion service, there is a possible missing permission check. This could lead to local escalation of In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-40079HIGHCVSS 7.8v14.0v142023-12-04
CVE-2023-40079 [HIGH] CVE-2023-40079: In injectSendIntentSender of ShortcutService.java, there is a possible background activity launch du In injectSendIntentSender of ShortcutService.java, there is a possible background activity launch due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2023-40087HIGHCVSS 8.8v11.0v12.0+8 more2023-12-04
CVE-2023-40087 [HIGH] CWE-787 CVE-2023-40087: In transcodeQ*ToFloat of btif_avrcp_audio_track.cc, there is a possible out of bounds write due to a In transcodeQ*ToFloat of btif_avrcp_audio_track.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2023-40091HIGHCVSS 7.8v11.0v12.0+8 more2023-12-04
CVE-2023-40091 [HIGH] CWE-787 CVE-2023-40091: In onTransact of IncidentService.cpp, there is a possible out of bounds write due to memory corrupti In onTransact of IncidentService.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2023-40095HIGHCVSS 7.8v11.0v12.0+8 more2023-12-04
CVE-2023-40095 [HIGH] CVE-2023-40095: In createDontSendToRestrictedAppsBundle of PendingIntentUtils.java, there is a possible background a In createDontSendToRestrictedAppsBundle of PendingIntentUtils.java, there is a possible background activity launch due to a missing check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2023-40088HIGHCVSS 8.8v11.0v12.0+8 more2023-12-04
CVE-2023-40088 [HIGH] CWE-416 CVE-2023-40088: In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2023-45774HIGHCVSS 7.8v11.0v12.0+8 more2023-12-04
CVE-2023-45774 [HIGH] CVE-2023-45774: In fixUpIncomingShortcutInfo of ShortcutService.java, there is a possible way to view another user's In fixUpIncomingShortcutInfo of ShortcutService.java, there is a possible way to view another user's image due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2023-32847HIGHCVSS 7.8v12.0v13.02023-12-04
CVE-2023-32847 [HIGH] CWE-787 CVE-2023-32847: In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08241940; Issue ID: ALPS08241940.
nvdandroid
CVE-2023-42691HIGHCVSS 7.8v11.0v12.0+1 more2023-12-04
CVE-2023-42691 [HIGH] CWE-862 CVE-2023-42691: In wifi service, there is a possible missing permission check. This could lead to local escalation o In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-42686HIGHCVSS 7.8v10.02023-12-04
CVE-2023-42686 [HIGH] CWE-862 CVE-2023-42686: In wifi service, there is a possible missing permission check. This could lead to local escalation o In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2023-45775HIGHCVSS 7.8v14.0v142023-12-04
CVE-2023-45775 [HIGH] CWE-787 CVE-2023-45775: In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvdandroid
CVE-2023-42692HIGHCVSS 7.8v10.02023-12-04
CVE-2023-42692 [HIGH] CWE-862 CVE-2023-42692: In wifi service, there is a possible missing permission check. This could lead to local escalation o In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd