Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 87 of 339
CVE-2021-39767P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39767 [HIGH] CWE-1188 CVE-2021-39767: In miniadb, there is a possible way to get read/write access to recovery system properties due to an
In miniadb, there is a possible way to get read/write access to recovery system properties due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-201308542
nvd
CVE-2021-39763P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39763 [HIGH] CWE-20 CVE-2021-39763: In Settings, there is a possible way to make the user enable WiFi due to improper input validation.
In Settings, there is a possible way to make the user enable WiFi due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-199176115
nvd
CVE-2021-39741P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-39741 [HIGH] CWE-787 CVE-2021-39741: In Keymaster, there is a possible out of bounds write due to a missing bounds check. This could lead
In Keymaster, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-173567719
nvd
CVE-2021-0486P3HIGHCVSS 7.8v10.0v11.0+1 more2021-07-14
CVE-2021-0486 [HIGH] CWE-276 CVE-2021-0486: In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external sto
In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-171430330
nvd
CVE-2021-0571P3HIGHCVSS 7.8v11.0vAndroid-112021-06-22
CVE-2021-0571 [HIGH] CWE-863 CVE-2021-0571: In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManager
In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of ActivityTaskManagerService.java and AppTaskImpl.java, there is possible access to restricted activities due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat
nvd
CVE-2023-21256P3HIGHCVSS 7.8v13.0v132023-07-13
CVE-2023-21256 [HIGH] CWE-863 CVE-2023-21256: In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Setting
In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2021-0547P3HIGHCVSS 7.8v11.0vAndroid-112021-06-22
CVE-2021-0547 [HIGH] CWE-862 CVE-2021-0547: In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled
In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL handler due to a missing permission check. This could lead to local escalation of privilege that may result in undefined behavior in some HAL implementations with no additional execution privileges needed. User interaction is not needed
nvd
CVE-2023-21034P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21034 [HIGH] CWE-863 CVE-2023-21034: In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due t
In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-230358834
nvd
CVE-2022-21743P3HIGHCVSS 7.8v9.0v10.0+2 more2022-05-03
CVE-2022-21743 [HIGH] CWE-190 CVE-2022-21743: In ion, there is a possible use after free due to an integer overflow. This could lead to local esca
In ion, there is a possible use after free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06371108; Issue ID: ALPS06371108.
nvd
CVE-2022-20109P3HIGHCVSS 7.8v9.0v10.0+2 more2022-05-03
CVE-2022-20109 [HIGH] CVE-2022-20109: In ion, there is a possible use after free due to improper update of reference count. This could lea
In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06399915; Issue ID: ALPS06399915.
nvd
CVE-2021-39776P3HIGHCVSS 7.8v12.0vAndroid-12L2022-03-30
CVE-2021-39776 [HIGH] CWE-416 CVE-2021-39776: In NFC, there is a possible memory corruption due to a use after free. This could lead to local esca
In NFC, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-192614125
nvd
CVE-2021-0539P3HIGHCVSS 7.8v11.0vAndroid-112021-06-22
CVE-2021-0539 [HIGH] CWE-862 CVE-2021-0539: In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversa
In archiveStoredConversation of MmsService.java, there is a possible way to archive message conversation without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A
nvd
CVE-2022-20297P3HIGHCVSS 7.8v13.0vAndroid-132022-08-12
CVE-2022-20297 [HIGH] CVE-2022-20297: In Settings, there is a possible way to bypass factory reset protections due to a logic error in the
In Settings, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-201561699
nvd
CVE-2022-20286P3HIGHCVSS 7.8v13.0vAndroid-132022-08-12
CVE-2022-20286 [HIGH] CVE-2022-20286: In Connectivity, there is a possible bypass the restriction of starting activity from background due
In Connectivity, there is a possible bypass the restriction of starting activity from background due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-230866011
nvd
CVE-2022-20292P3HIGHCVSS 7.8v13.0vAndroid-132022-08-12
CVE-2022-20292 [HIGH] CVE-2022-20292: In Settings, there is a possible way to bypass factory reset protections due to a logic error in the
In Settings, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-202975040
nvd
CVE-2023-20971P3HIGHCVSS 7.8v13.0v14+3 more2023-03-24
CVE-2023-20971 [HIGH] CWE-863 CVE-2023-20971: In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerou
In removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2022-20415P3HIGHCVSS 7.8v10.0v11.0+4 more2022-10-11
CVE-2022-20415 [HIGH] CVE-2022-20415: In handleFullScreenIntent of StatusBarNotificationActivityStarter.java, there is a possible bypass o
In handleFullScreenIntent of StatusBarNotificationActivityStarter.java, there is a possible bypass of the restriction of starting activity from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A
nvd
CVE-2021-0922P3HIGHCVSS 7.8v11.0vAndroid-112021-12-15
CVE-2021-0922 [HIGH] CWE-862 CVE-2021-0922: In enforceCrossUserOrProfilePermission of PackageManagerService.java, there is a possible bypass of
In enforceCrossUserOrProfilePermission of PackageManagerService.java, there is a possible bypass of INTERACT_ACROSS_PROFILES permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Andr
nvd
CVE-2021-39806P3HIGHCVSS 7.8v12.1vAndroid-12L2022-06-15
CVE-2021-39806 [HIGH] CWE-415 CVE-2021-39806: In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double fre
In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege during startup of servicemanager, if an attacker can trigger an initialization failure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV
nvd
CVE-2021-39807P3HIGHCVSS 7.8v10.0v11.0+3 more2022-04-12
CVE-2021-39807 [HIGH] CWE-269 CVE-2021-39807: In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Gu
In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 A
nvd