Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 84 of 339
CVE-2021-39630P3HIGHCVSS 7.8v12.0vAndroid-122022-01-14
CVE-2021-39630 [HIGH] CWE-863 CVE-2021-39630: In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overl
In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-202768292
nvd
CVE-2021-39622P3HIGHCVSS 7.8v10.0v11.0+2 more2022-01-14
CVE-2021-39622 [HIGH] CWE-862 CVE-2021-39622: In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission ch
In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-192663648
nvd
CVE-2022-20203P3HIGHCVSS 7.8v12.1vAndroid-12L2022-06-15
CVE-2022-20203 [HIGH] CWE-787 CVE-2022-20203: In multiple locations of the nanopb library, there is a possible way to corrupt memory when decoding
In multiple locations of the nanopb library, there is a possible way to corrupt memory when decoding untrusted protobuf files. This could lead to local escalation of privilege,with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2021-39697P3HIGHCVSS 7.8v11.0v12.0+1 more2022-03-16
CVE-2021-39697 [HIGH] CWE-862 CVE-2021-39697: In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external stor
In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12
nvd
CVE-2021-39694P3HIGHCVSS 7.8v12.0vAndroid-122022-03-16
CVE-2021-39694 [HIGH] CWE-276 CVE-2021-39694: In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly
In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-202312327
nvd
CVE-2022-20048P3HIGHCVSS 7.8v10.0v11.0+1 more2022-03-10
CVE-2022-20048 [HIGH] CWE-787 CVE-2022-20048: In video decoder, there is a possible out of bounds write due to a missing bounds check. This could
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05917502; Issue ID: ALPS05917502.
nvd
CVE-2022-20047P3HIGHCVSS 7.8v10.0v11.0+1 more2022-03-10
CVE-2022-20047 [HIGH] CWE-787 CVE-2022-20047: In video decoder, there is a possible out of bounds write due to a missing bounds check. This could
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05917489; Issue ID: ALPS05917489.
nvd
CVE-2021-39676P3HIGHCVSS 7.8v11.0vAndroid-112022-02-11
CVE-2021-39676 [HIGH] CWE-20 CVE-2021-39676: In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mi
In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-197228210
nvd
CVE-2024-43080P3HIGHCVSS 7.8v12.0v12.1+8 more2024-11-13
CVE-2024-43080 [HIGH] CWE-502 CVE-2024-43080: In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to uns
In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2021-39632P3HIGHCVSS 7.8v11.0v12.0+1 more2022-01-14
CVE-2021-39632 [HIGH] CWE-787 CVE-2021-39632: In inotify_cb of events.cpp, there is a possible out of bounds write due to an incorrect bounds chec
In inotify_cb of events.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-202159709
nvd
CVE-2021-0649P3HIGHCVSS 7.8v11.0vAndroid-112021-12-15
CVE-2021-0649 [HIGH] CWE-863 CVE-2021-0649: In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. Th
In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-191382886
nvd
CVE-2021-39703P3HIGHCVSS 7.8v12.0vAndroid-122022-03-16
CVE-2021-39703 [HIGH] CWE-610 CVE-2021-39703: In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a c
In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-207057578
nvd
CVE-2021-0932P3HIGHCVSS 7.8v10.0vAndroid-102021-12-15
CVE-2021-0932 [HIGH] CVE-2021-0932: In showNotification of NavigationModeController.java, there is a possible confused deputy due to an
In showNotification of NavigationModeController.java, there is a possible confused deputy due to an unsafe PendingIntent. This could lead to local escalation of privilege that allows actions performed as the System UI with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-173025705
nvd
CVE-2023-20964P3HIGHCVSS 7.8v12.0v12.1+2 more2023-03-24
CVE-2023-20964 [HIGH] CWE-610 CVE-2023-20964: In multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a co
In multiple functions of MediaSessionRecord.java, there is a possible Intent rebroadcast due to a confused deputy. This could lead to local denial of service or escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A
nvd
CVE-2021-39738P3HIGHCVSS 7.8v10.0v11.0+3 more2022-05-10
CVE-2021-39738 [HIGH] CWE-862 CVE-2021-39738: In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permi
In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-216190509
nvd
CVE-2022-20053P3HIGHCVSS 7.8v9.0v10.0+2 more2022-03-10
CVE-2022-20053 [HIGH] CWE-862 CVE-2022-20053: In ims service, there is a possible escalation of privilege due to a missing permission check. This
In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219097; Issue ID: ALPS06219097.
nvd
CVE-2021-0799P3HIGHCVSS 7.8v12.0vAndroid-122021-12-15
CVE-2021-0799 [HIGH] CVE-2021-0799: In ActivityThread.java, there is a possible way to collide the content provider's authorities. This
In ActivityThread.java, there is a possible way to collide the content provider's authorities. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197647956
nvd
CVE-2021-0646P3HIGHCVSS 7.8v8.1v9.0+3 more2021-08-17
CVE-2021-0646 [HIGH] CWE-787 CVE-2021-0646: In sqlite3_str_vappendf of sqlite3.c, there is a possible out of bounds write due to improper input
In sqlite3_str_vappendf of sqlite3.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if the user can also inject a printf into a privileged process's SQL with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andr
nvd
CVE-2020-0357P3HIGHCVSS 7.8v11.0vAndroid-112020-09-17
CVE-2020-0357 [HIGH] CWE-416 CVE-2020-0357: In SurfaceFlinger, there is a possible use-after-free due to improper locking. This could lead to lo
In SurfaceFlinger, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150225569
nvd
CVE-2021-0487P3HIGHCVSS 7.8v11.0vAndroid-112021-06-11
CVE-2021-0487 [HIGH] CWE-1021 CVE-2021-0487: In onCreate of CalendarDebugActivity.java, there is a possible way to export calendar data to the sd
In onCreate of CalendarDebugActivity.java, there is a possible way to export calendar data to the sdcard without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174046
nvd