Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 88 of 339
CVE-2021-0999P3HIGHCVSS 7.8v12.0vAndroid-122021-12-15
CVE-2021-0999 [HIGH] CWE-862 CVE-2021-0999: In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetoot
In the broadcast definition in AndroidManifest.xml, there is a possible way to set the A2DP bluetooth device connection state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A
nvd
CVE-2023-40110P3HIGHCVSS 7.8v11.0v12.0+8 more2024-02-15
CVE-2023-40110 [HIGH] CWE-787 CVE-2023-40110: In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer
In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-26471P3HIGHCVSS 7.8v12.02022-10-07
CVE-2022-26471 [HIGH] CWE-502 CVE-2022-26471: In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This coul
In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07319121; Issue ID: ALPS07319121.
nvd
CVE-2022-20325P3HIGHCVSS 7.8v13.0vAndroid-132022-08-12
CVE-2022-20325 [HIGH] CWE-416 CVE-2022-20325: In Media, there is a possible code execution due to a use after free. This could lead to local escal
In Media, there is a possible code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-186473060
nvd
CVE-2022-20392P3HIGHCVSS 7.8v10.0v11.0+3 more2022-09-13
CVE-2022-20392 [HIGH] CWE-20 CVE-2022-20392: In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dan
In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent due to improper input validation. This could lead to local escalation of privilege during app installation or upgrade with no additional execution privileges needed. User interaction is not needed for exploitation.P
nvd
CVE-2022-20204P3HIGHCVSS 7.8v12.1vAndroid-12L2022-06-15
CVE-2022-20204 [HIGH] CWE-862 CVE-2022-20204: In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reportin
In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid I
nvd
CVE-2023-21183P3HIGHCVSS 7.8v13.0vAndroid-132023-06-28
CVE-2023-21183 [HIGH] CVE-2023-21183: In ForegroundUtils of ForegroundUtils.java, there is a possible way to read NFC tag data while the a
In ForegroundUtils of ForegroundUtils.java, there is a possible way to read NFC tag data while the app is still in the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-23
nvd
CVE-2023-21093P3HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21093 [HIGH] CWE-22 CVE-2023-21093: In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory bel
In extractRelativePath of FileUtils.java, there is a possible way to access files in a directory belonging to other applications due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 A
nvd
CVE-2022-20248P3HIGHCVSS 7.8v13.0.0vAndroid-132022-08-11
CVE-2022-20248 [HIGH] CVE-2022-20248: In Settings, there is a possible way to connect to an open network bypassing DISALLOW_CONFIG_WIFI re
In Settings, there is a possible way to connect to an open network bypassing DISALLOW_CONFIG_WIFI restriction due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-227619193
nvd
CVE-2021-1000P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-1000 [HIGH] CWE-276 CVE-2021-1000: In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission
In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-185190688
nvd
CVE-2021-1033P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2021-1033 [HIGH] CWE-276 CVE-2021-1033: In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission byp
In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-185247656
nvd
CVE-2022-20002P3HIGHCVSS 7.8v12.1vAndroid-12L2022-03-30
CVE-2022-20002 [HIGH] CWE-862 CVE-2022-20002: In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check.
In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-198657657
nvd
CVE-2023-21024P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21024 [HIGH] CWE-693 CVE-2023-21024: In maybeFinish of FallbackHome.java, there is a possible delay of lockdown screen due to logic error
In maybeFinish of FallbackHome.java, there is a possible delay of lockdown screen due to logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246543238
nvd
CVE-2021-39784P3HIGHCVSS 7.8v12.0vAndroid-12L2022-03-30
CVE-2021-39784 [HIGH] CWE-269 CVE-2021-39784: In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a mis
In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-200163477
nvd
CVE-2023-21088P3HIGHCVSS 7.8v12.0v12.1+2 more2023-04-19
CVE-2023-21088 [HIGH] CVE-2023-21088: In deliverOnFlushComplete of LocationProviderManager.java, there is a possible way to bypass backgro
In deliverOnFlushComplete of LocationProviderManager.java, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L
nvd
CVE-2022-21777P3HIGHCVSS 7.8v11.0v12.02022-07-06
CVE-2022-21777 [HIGH] CWE-862 CVE-2022-21777: In Autoboot, there is a possible permission bypass due to a missing permission check. This could lea
In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06713894; Issue ID: ALPS06713894.
nvd
CVE-2023-44122P3HIGHCVSS 7.8v12.0v13.02023-09-27
CVE-2023-44122 [HIGH] CWE-927 CVE-2023-44122: The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("c
The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreensettings") app in the "com/lge/lockscreensettings/dynamicwallpaper/MyCategoryGuideActivity.java" file. The main problem is that the app launches implicit intents that can be intercepted by third-party apps installed on the same device.
nvd
CVE-2023-20906P3HIGHCVSS 7.8v11.0v12.0+3 more2023-03-24
CVE-2023-20906 [HIGH] CVE-2023-20906: In onPackageAddedInternal of PermissionManagerService.java, there is a possible way to silently gran
In onPackageAddedInternal of PermissionManagerService.java, there is a possible way to silently grant a permission after a Target SDK update due to a permissions bypass. This could lead to local escalation of privilege after updating an app to a higher Target SDK with no additional execution privileges needed. User interaction is not needed for exploitation.P
nvd
CVE-2022-20084P3HIGHCVSS 7.8v10.0v11.0+1 more2022-05-03
CVE-2022-20084 [HIGH] CWE-862 CVE-2022-20084: In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing per
In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06498874; Issue ID: ALPS06498874.
nvd
CVE-2022-20093P3HIGHCVSS 7.8v10.0v11.0+1 more2022-05-03
CVE-2022-20093 [HIGH] CWE-862 CVE-2022-20093: In telephony, there is a possible way to disable receiving SMS messages due to a missing permission
In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06498868; Issue ID: ALPS06498868.
nvd