Google Android vulnerabilities
6,770 known vulnerabilities affecting google/android.
Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36
Vulnerabilities
Page 96 of 339
CVE-2021-25479P3HIGHCVSS 7.2v8.1v9.0+2 more2021-10-06
CVE-2021-25479 [HIGH] CWE-122 CVE-2021-25479: A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Relea
A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.
nvd
CVE-2015-3863P3CRITICALCVSS 9.3≤ 5.12015-10-01
CVE-2015-3863 [CRITICAL] CWE-189 CVE-2015-3863: Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before
Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary code and read arbitrary Keystore keys via an application that uses a crafted blob in an insert operation, aka internal bug 22802399.
nvd
CVE-2025-26443P3HIGHCVSS 7.3v13.0v14.0+4 more2025-09-04
CVE-2025-26443 [HIGH] CWE-693 CVE-2025-26443: In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing i
In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2022-27574P3HIGHCVSS 7.2v10.0v11.0+1 more2022-04-11
CVE-2022-27574 [HIGH] CWE-20 CVE-2022-27574: Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsi
Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attacker.
nvd
CVE-2024-40653P3HIGHCVSS 7.3v13.0v14.0+4 more2025-09-02
CVE-2024-40653 [HIGH] CWE-287 CVE-2024-40653: In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permissi
In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-48634P3HIGHCVSS 7.3v14.0v15.0+4 more2026-03-02
CVE-2025-48634 [HIGH] CWE-862 CVE-2025-48634: In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing
In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
nvd
CVE-2025-22427P3HIGHCVSS 7.3v13.0v14.0+4 more2025-09-02
CVE-2025-22427 [HIGH] CWE-693 CVE-2025-22427: In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notific
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above the lock screen due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-48556P3HIGHCVSS 7.3v15.0v16.0+2 more2025-09-04
CVE-2025-48556 [HIGH] CWE-20 CVE-2025-48556: In multiple methods of NotificationChannel.java, there is a possible desynchronization from persiste
In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2025-22439P3HIGHCVSS 7.3v13.0v14.0+4 more2025-09-02
CVE-2025-22439 [HIGH] CWE-862 CVE-2025-22439: In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restr
In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2023-45866P3MEDIUMCVSS 6.3v4.2.2v6.0.1+4 more2023-12-08
CVE-2023-45866 [MEDIUM] CVE-2023-45866: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate an
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ub
nvd
CVE-2022-26099P3CRITICALCVSS 9.1v10.0v11.0+1 more2022-04-11
CVE-2022-26099 [CRITICAL] CWE-476 CVE-2022-26099: Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-
Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.
nvd
CVE-2019-20597P3CRITICALCVSS 9.1v7.1.0v8.0+2 more2020-03-24
CVE-2019-20597 [CRITICAL] CWE-347 CVE-2019-20597: An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. SPENgest
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. SPENgesture allows arbitrary applications to read or modify user-input logs. The Samsung ID is SVE-2019-14170 (June 2019).
nvd
CVE-2015-1537P3HIGHCVSS 7.8≤ 4.4.42017-09-28
CVE-2015-1537 [HIGH] CWE-190 CVE-2015-1537: Integer overflow in IHDCP.cpp in the media_server component in Android allows remote attackers to ex
Integer overflow in IHDCP.cpp in the media_server component in Android allows remote attackers to execute arbitrary code via a crafted application.
nvd
CVE-2016-2464P3HIGHCVSS 7.8v4.0v4.0.1+16 more2016-06-13
CVE-2016-2464 [HIGH] CWE-20 CVE-2016-2464: libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1
libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted mkv file, aka internal bug 23167726.
nvd
CVE-2018-21070P3HIGHCVSS 8.4v7.0v7.1.0+3 more2020-04-08
CVE-2018-21070 [HIGH] CWE-354 CVE-2018-21070: An issue was discovered on Samsung mobile devices with N(7.x), O(8.0) devices (MSM8998 or SDM845 chi
An issue was discovered on Samsung mobile devices with N(7.x), O(8.0) devices (MSM8998 or SDM845 chipsets) software. An attacker can bypass Secure Boot and obtain root access because of a missing Bootloader integrity check. The Samsung ID is SVE-2018-11552 (May 2018).
nvd
CVE-2017-0505P3HIGHCVSS 7.8≤ 7.1.12017-03-08
CVE-2017-0505 [HIGH] CVE-2017-0505: An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driv
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, whi
nvd
CVE-2017-0760P3HIGHCVSS 7.8v6.0v6.0.1+4 more2017-09-08
CVE-2017-0760 [HIGH] CWE-755 CVE-2017-0760: A remote code execution vulnerability in the Android media framework (libstagefright). Product: Andr
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237396.
nvd
CVE-2017-0764P3HIGHCVSS 7.8v4.0v4.0.1+28 more2017-09-08
CVE-2017-0764 [HIGH] CVE-2017-0764: A remote code execution vulnerability in the Android media framework (libvorbis). Product: Android.
A remote code execution vulnerability in the Android media framework (libvorbis). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62872015.
nvd
CVE-2017-0761P3HIGHCVSS 7.8v6.0v6.0.1+5 more2017-09-08
CVE-2017-0761 [HIGH] CWE-119 CVE-2017-0761: A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Ver
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38448381.
nvd
CVE-2017-0758P3HIGHCVSS 7.8v5.0v5.0.1+10 more2017-09-08
CVE-2017-0758 [HIGH] CWE-119 CVE-2017-0758: A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Ve
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492741.
nvd