Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 90 of 339
CVE-2024-23707P3HIGHCVSS 7.8v14.0v142024-05-07
CVE-2024-23707 [HIGH] CWE-20 CVE-2024-23707: In multiple locations, there is a possible permissions bypass due to improper input validation. This
In multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-21099P3HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21099 [HIGH] CVE-2023-21099: In multiple methods of PackageInstallerSession.java, there is a possible way to start foreground ser
In multiple methods of PackageInstallerSession.java, there is a possible way to start foreground services from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-
nvd
CVE-2023-21030P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21030 [HIGH] CWE-415 CVE-2023-21030: In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double fr
In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-226234140
nvd
CVE-2023-20993P3HIGHCVSS 7.8v13.0vAndroid-11 Android-12 Android-12L Android-132023-03-24
CVE-2023-20993 [HIGH] CWE-755 CVE-2023-20993: In multiple functions of SnoozeHelper.java, there is a possible failure to persist settings due to a
In multiple functions of SnoozeHelper.java, there is a possible failure to persist settings due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-26
nvd
CVE-2023-21017P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21017 [HIGH] CVE-2023-21017: In InstallStart of InstallStart.java, there is a possible way to change the installer package name d
In InstallStart of InstallStart.java, there is a possible way to change the installer package name due to an improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-236687884
nvd
CVE-2022-47361P3HIGHCVSS 7.8v10.0v11.0+1 more2023-02-12
CVE-2022-47361 [HIGH] CWE-862 CVE-2022-47361: In firewall service, there is a missing permission check. This could lead to local escalation of pri
In firewall service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
nvd
CVE-2022-26429P3HIGHCVSS 7.8v11.0v12.02022-08-01
CVE-2022-26429 [HIGH] CWE-862 CVE-2022-26429: In cta, there is a possible way to write permission usage records of an app due to a missing permiss
In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07025415; Issue ID: ALPS07025415.
nvd
CVE-2022-32635P3HIGHCVSS 7.8v10.0v11.0+2 more2023-01-03
CVE-2022-32635 [HIGH] CWE-787 CVE-2022-32635: In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07573237; Issue ID: ALPS07573237.
nvd
CVE-2022-39119P3HIGHCVSS 7.8v10.0v11.0+1 more2022-09-09
CVE-2022-39119 [HIGH] CWE-862 CVE-2022-39119: In network service, there is a missing permission check. This could lead to local escalation of priv
In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
nvd
CVE-2022-20281P3HIGHCVSS 7.8v13.0vAndroid-132022-08-12
CVE-2022-20281 [HIGH] CWE-862 CVE-2022-20281: In Core, there is a possible way to start an activity from the background due to a missing permissio
In Core, there is a possible way to start an activity from the background due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-204083967
nvd
CVE-2019-9367P3HIGHCVSS 7.5v10.0vAndroid-102019-09-27
CVE-2019-9367 [HIGH] CWE-125 CVE-2019-9367: In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112106425
nvd
CVE-2023-21324P3HIGHCVSS 7.8fixed in 14.0v142023-10-30
CVE-2023-21324 [HIGH] CWE-203 CVE-2023-21324: In Package Installer, there is a possible way to determine whether an app is installed, without quer
In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21187P3HIGHCVSS 7.8v13.0vAndroid-132023-06-28
CVE-2023-21187 [HIGH] CWE-276 CVE-2023-21187: In onCreate of UsbAccessoryUriActivity.java, there is a possible way to escape the Setup Wizard due
In onCreate of UsbAccessoryUriActivity.java, there is a possible way to escape the Setup Wizard due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-246542917
nvd
CVE-2023-21135P3HIGHCVSS 7.8v11.0v12.0+3 more2023-06-15
CVE-2023-21135 [HIGH] CWE-20 CVE-2023-21135: In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications
In onCreate of NotificationAccessSettings.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Andro
nvd
CVE-2022-20349P3HIGHCVSS 7.8v10.0v11.0+3 more2022-08-10
CVE-2022-20349 [HIGH] CWE-862 CVE-2022-20349: In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible a
In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 A
nvd
CVE-2023-21083P3HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21083 [HIGH] CVE-2023-21083: In onNullBinding of CallScreeningServiceHelper.java, there is a possible way to record audio without
In onNullBinding of CallScreeningServiceHelper.java, there is a possible way to record audio without showing a privacy indicator due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android
nvd
CVE-2023-20995P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-20995 [HIGH] CWE-269 CVE-2023-20995: In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock du
In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-241910279
nvd
CVE-2022-20398P3HIGHCVSS 7.8v13.0vAndroid-132022-09-13
CVE-2022-20398 [HIGH] CWE-732 CVE-2022-20398: In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure
In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-221859734
nvd
CVE-2023-35666P3HIGHCVSS 7.8v11.0v12.0+6 more2023-09-11
CVE-2023-35666 [HIGH] CWE-416 CVE-2023-35666: In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the co
In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2023-21092P3HIGHCVSS 7.8v11.0v12.0+3 more2023-04-19
CVE-2023-21092 [HIGH] CWE-20 CVE-2023-21092: In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a B
In retrieveServiceLocked of ActiveServices.java, there is a possible way to dynamically register a BroadcastReceiver using permissions of System App due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:
nvd