Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 1 of 29
CVE-2023-20963P1UNKNOWNKEVPoC≥ 13-next:0, < 13-next:2023-03-01≥ 11:0, < 11:2023-03-01+3 more2023-03-01
CVE-2023-20963 CVE-2023-20963: In WorkSource, there is a possible parcel mismatch
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48572P1UNKNOWNKEV≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48572 CVE-2025-48572: In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-32896P1UNKNOWNKEV≥ 14-next:0, < 14-next:2024-06-05≥ 14:0, < 14:2024-06-052024-06-01
CVE-2024-32896 CVE-2024-32896: there is a possible way to bypass due to a logic error in the code
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-35674P1UNKNOWNKEV≥ 13-next:0, < 13-next:2023-09-01≥ 11:0, < 11:2023-09-01+3 more2023-09-01
CVE-2023-35674 CVE-2023-35674: In onCreate of WindowState
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43093P1UNKNOWNKEV≥ 15-next:0, < 15-next:2025-03-01≥ 12:0, < 12:2025-03-01+4 more2025-03-01
CVE-2024-43093 CVE-2024-43093: In shouldHideDocument of ExternalStorageProvider
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-48633P1UNKNOWNKEV≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48633 CVE-2025-48633: In hasAccountsOnAnyUser of DevicePolicyManagerService
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21237P2UNKNOWNKEV≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21237 CVE-2023-21237: In applyRemoteView of NotificationContentInflater
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20145P2UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 11:0, < 11:2022-06-012022-06-01
CVE-2022-20145 CVE-2022-20145: In startLegacyVpnPrivileged of Vpn
In startLegacyVpnPrivileged of Vpn.java, there is a possible way to retrieve VPN credentials due to a protocol downgrade attack. This could lead to remote escalation of privilege if a malicious Wi-Fi AP is used, with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22429P2UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2025-22429 CVE-2025-22429: In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code
In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48626P2UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48626 CVE-2025-48626: In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure
In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20918P3UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 11:0, < 11:2023-07-01+3 more2023-07-01
CVE-2023-20918 CVE-2023-20918: In getPendingIntentLaunchFlags of ActivityOptions
In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48602P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+2 more2026-03-01
CVE-2025-48602 CVE-2025-48602: In exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator
In exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32313P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+2 more2026-03-01
CVE-2025-32313 CVE-2025-32313: In UsageEvents of UsageEvents
In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48645P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+3 more2026-03-01
CVE-2025-48645 CVE-2025-48645: In loadDescription of DeviceAdminInfo
In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2026-0025P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+3 more2026-03-01
CVE-2026-0025 CVE-2026-0025: In hasImage of Notification
In hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2026-0020P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+3 more2026-03-01
CVE-2026-0020 CVE-2026-0020: In parsePermissionGroup of ParsedPermissionUtils
In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48574P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+2 more2026-03-01
CVE-2025-48574 CVE-2025-48574: In validateAddingWindowLw of DisplayPolicy
In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2026-0034P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+3 more2026-03-01
CVE-2026-0034 CVE-2026-0034: In setPackageOrComponentEnabled of ManagedServices
In setPackageOrComponentEnabled of ManagedServices.java, there is a possible notification policy desync due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22437P3UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 13:0, < 13:2025-04-012025-04-01
CVE-2025-22437 CVE-2025-22437: In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in the code
In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31317P3UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 12:0, < 12:2024-06-01+3 more2024-06-01
CVE-2024-31317 CVE-2024-31317: In multiple functions of ZygoteProcess
In multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to unsafe deserialization. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
1 / 29Next →