Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 83 of 339
CVE-2022-20041P3HIGHCVSS 7.8v8.1v9.0+3 more2022-02-09
CVE-2022-20041 [HIGH] CWE-862 CVE-2022-20041: In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This co
In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108596; Issue ID: ALPS06108596.
nvd
CVE-2022-20542P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2022-20542 [HIGH] CWE-20 CVE-2022-20542: In parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds che
In parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238083570
nvd
CVE-2021-39619P3HIGHCVSS 7.8v11.0v12.0+1 more2022-02-11
CVE-2021-39619 [HIGH] CVE-2021-39619: In updatePackageMappingsData of UsageStatsService.java, there is a possible way to bypass security a
In updatePackageMappingsData of UsageStatsService.java, there is a possible way to bypass security and privacy settings of app usage due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Androi
nvd
CVE-2020-0485P3HIGHCVSS 7.8v11.0vAndroid-112020-12-15
CVE-2020-0485 [HIGH] CWE-862 CVE-2020-0485: In areFunctionsSupported of UsbBackend.java, there is a possible access to tethering from a guest ac
In areFunctionsSupported of UsbBackend.java, there is a possible access to tethering from a guest account due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-166125765
nvd
CVE-2021-0957P3HIGHCVSS 7.8v10.0v11.0+2 more2022-03-16
CVE-2021-0957 [HIGH] CVE-2021-0957: In NotificationStackScrollLayout of NotificationStackScrollLayout.java, there is a possible way to b
In NotificationStackScrollLayout of NotificationStackScrollLayout.java, there is a possible way to bypass Factory Reset Protections. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-193149550
nvd
CVE-2021-39695P3HIGHCVSS 7.8v11.0vAndroid-112022-03-16
CVE-2021-39695 [HIGH] CWE-281 CVE-2021-39695: In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error
In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-209607944
nvd
CVE-2021-0984P3HIGHCVSS 7.8v12.0vAndroid-122021-12-15
CVE-2021-0984 [HIGH] CWE-404 CVE-2021-0984: In onNullBinding of ManagedServices.java, there is a possible permission bypass due to an incorrectl
In onNullBinding of ManagedServices.java, there is a possible permission bypass due to an incorrectly unbound service. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-192475653
nvd
CVE-2021-39709P3HIGHCVSS 7.8v12.0vAndroid-122022-03-16
CVE-2021-39709 [HIGH] CVE-2021-39709: In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission byp
In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-208817618
nvd
CVE-2021-0927P3HIGHCVSS 7.8v8.1v9.0+4 more2021-12-15
CVE-2021-0927 [HIGH] CWE-281 CVE-2021-0927: In requestChannelBrowsable of TvInputManagerService.java, there is a possible permission bypass due
In requestChannelBrowsable of TvInputManagerService.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9A
nvd
CVE-2020-0420P3HIGHCVSS 7.8v11.0vAndroid-112020-10-14
CVE-2020-0420 [HIGH] CWE-667 CVE-2020-0420: In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing
In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-162383705
nvd
CVE-2021-0341P3HIGHCVSS 7.5v8.1v9.0+3 more2021-02-10
CVE-2021-0341 [HIGH] CWE-295 CVE-2021-0341: In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for th
In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due to improperly used crypto. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Andro
nvd
CVE-2021-39693P3HIGHCVSS 7.8v12.0vAndroid-122022-03-16
CVE-2021-39693 [HIGH] CWE-119 CVE-2021-39693: In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a vis
In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-208662370
nvd
CVE-2021-0921P3HIGHCVSS 7.8v11.0vAndroid-112021-12-15
CVE-2021-0921 [HIGH] CWE-20 CVE-2021-0921: In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deseriali
In ParsingPackageImpl of ParsingPackageImpl.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-195962697
nvd
CVE-2021-0398P3HIGHCVSS 7.8v11.0vAndroid-112021-03-10
CVE-2021-0398 [HIGH] CVE-2021-0398: In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a
In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-173516292
nvd
CVE-2022-39093P3HIGHCVSS 7.8v10.0v11.0+1 more2022-12-06
CVE-2022-39093 [HIGH] CWE-862 CVE-2022-39093: In power management service, there is a missing permission check. This could lead to set up power ma
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
nvd
CVE-2021-0429P3HIGHCVSS 7.8v8.1v9.0+3 more2021-04-13
CVE-2021-0429 [HIGH] CWE-416 CVE-2021-0429: In pollOnce of ALooper.cpp, there is possible memory corruption due to a use after free. This could
In pollOnce of ALooper.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-175074139
nvd
CVE-2022-20548P3HIGHCVSS 7.8v13.0vAndroid-132022-12-16
CVE-2022-20548 [HIGH] CWE-787 CVE-2022-20548: In setParameter of EqualizerEffect.cpp, there is a possible out of bounds write due to improper inpu
In setParameter of EqualizerEffect.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-240919398
nvd
CVE-2022-20475P3HIGHCVSS 7.8v11.0v12.0+3 more2022-12-13
CVE-2022-20475 [HIGH] CWE-276 CVE-2022-20475: In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTask
In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L And
nvd
CVE-2020-0025P3HIGHCVSS 7.8v11.0vAndroid-112021-03-10
CVE-2020-0025 [HIGH] CVE-2020-0025: In deletePackageVersionedInternal of PackageManagerService.java, there is a possible way to exit Scr
In deletePackageVersionedInternal of PackageManagerService.java, there is a possible way to exit Screen Pinning due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-135604684
nvd
CVE-2023-20917P3HIGHCVSS 7.8v11.0v12.0+3 more2023-03-24
CVE-2023-20917 [HIGH] CVE-2023-20917: In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a
In onTargetSelected of ResolverActivity.java, there is a possible way to share a wrong file due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-242605
nvd