Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 92 of 339
CVE-2022-42778P3HIGHCVSS 7.8v11.02022-12-06
CVE-2022-42778 [HIGH] CWE-862 CVE-2022-42778: In windows manager service, there is a missing permission check. This could lead to set up windows m
In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed.
nvd
CVE-2023-21175P3HIGHCVSS 7.8v13.0vAndroid-132023-06-28
CVE-2023-21175 [HIGH] CWE-276 CVE-2023-21175: In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disab
In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disable mobile data due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262243574
nvd
CVE-2023-52351P3HIGHCVSS 7.8v12.0v13.0+1 more2024-04-08
CVE-2023-52351 [HIGH] CWE-787 CVE-2023-52351: In ril service, there is a possible out of bounds write due to a missing bounds check. This could le
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
nvd
CVE-2023-20957P3HIGHCVSS 7.8v11.0v12.0+2 more2023-03-24
CVE-2023-20957 [HIGH] CWE-266 CVE-2023-20957: In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protecti
In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset Protections due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-25842
nvd
CVE-2023-20959P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-20959 [HIGH] CWE-862 CVE-2023-20959: In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missin
In AddSupervisedUserActivity, guest users are not prevented from starting the activity due to missing permissions checks. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-249057848
nvd
CVE-2022-20246P3HIGHCVSS 7.8v13.0.0vAndroid-132022-08-11
CVE-2022-20246 [HIGH] CWE-276 CVE-2022-20246: In WindowManager, there is a possible bypass of the restrictions for starting activities from the ba
In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-2304931
nvd
CVE-2025-20645P3HIGHCVSS 7.8v14.0v15.02025-03-03
CVE-2025-20645 [HIGH] CWE-787 CVE-2025-20645: In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lea
In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09475476; Issue ID: MSV-2599.
nvd
CVE-2023-21001P3HIGHCVSS 7.8v13.0vAndroid-132023-03-24
CVE-2023-21001 [HIGH] CWE-862 CVE-2023-21001: In onContextItemSelected of NetworkProviderSettings.java, there is a possible way for users to chang
In onContextItemSelected of NetworkProviderSettings.java, there is a possible way for users to change the Wi-Fi settings of other users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13A
nvd
CVE-2023-30928P3HIGHCVSS 7.8v10.0v11.0+2 more2023-07-12
CVE-2023-30928 [HIGH] CWE-862 CVE-2023-30928: In telephony service, there is a possible missing permission check. This could lead to local escalat
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2023-30929P3HIGHCVSS 7.8v10.0v11.0+2 more2023-07-12
CVE-2023-30929 [HIGH] CWE-862 CVE-2023-30929: In telephony service, there is a possible missing permission check. This could lead to local escalat
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2023-30864P3HIGHCVSS 7.8v10.02023-06-06
CVE-2023-30864 [HIGH] CWE-862 CVE-2023-30864: In Connectivity Service, there is a possible missing permission check. This could lead to local esca
In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2023-30863P3HIGHCVSS 7.8v10.02023-06-06
CVE-2023-30863 [HIGH] CWE-862 CVE-2023-30863: In Connectivity Service, there is a possible missing permission check. This could lead to local esca
In Connectivity Service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2023-20927P3HIGHCVSS 7.8v13.0vAndroid-132023-02-15
CVE-2023-20927 [HIGH] CWE-284 CVE-2023-20927: In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to
In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-244216503
nvd
CVE-2022-48390P3HIGHCVSS 7.8v10.0v11.0+1 more2023-06-06
CVE-2022-48390 [HIGH] CWE-862 CVE-2022-48390: In telephony service, there is a possible missing permission check. This could lead to local escalat
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2022-48392P3HIGHCVSS 7.8v10.0v11.0+2 more2023-06-06
CVE-2022-48392 [HIGH] CWE-862 CVE-2022-48392: In dialer service, there is a possible missing permission check. This could lead to local escalation
In dialer service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
nvd
CVE-2023-20950P3HIGHCVSS 7.8v11.0v12.0+2 more2023-04-19
CVE-2023-20950 [HIGH] CWE-863 CVE-2023-20950: In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background a
In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restrictions via a pendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L
nvd
CVE-2023-21138P3HIGHCVSS 7.8v11.0v12.0+3 more2023-06-15
CVE-2023-21138 [HIGH] CWE-20 CVE-2023-21138: In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to
In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L
nvd
CVE-2023-21121P3HIGHCVSS 7.8v11.0v12.0+1 more2023-06-15
CVE-2023-21121 [HIGH] CWE-20 CVE-2023-21121: In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting
In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12An
nvd
CVE-2024-40655P3HIGHCVSS 7.8v12.0v12.1+6 more2024-09-11
CVE-2024-40655 [HIGH] CWE-276 CVE-2024-40655: In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maint
In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use permission in the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2024-40652P3HIGHCVSS 7.8v12.0v12.1+6 more2024-09-11
CVE-2024-40652 [HIGH] CWE-862 CVE-2024-40652: In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app whi
In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd