cbcvebase.

Platform Frameworks Base vulnerabilities

579 known vulnerabilities affecting platform/frameworks_base.

Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579

Vulnerabilities

Page 16 of 29
CVE-2024-31324P3UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 12:0, < 12:2024-06-01+3 more2024-06-01
CVE-2024-31324 CVE-2024-31324: In hide of WindowState In hide of WindowState.java, there is a possible way to bypass tapjacking/overlay protection by launching the activity in portrait mode first and then rotating it to landscape mode. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-21129P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21129 CVE-2023-21129: In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible activity launch while the app is in the background due to a BAL bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-48631P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+3 more2026-03-01
CVE-2025-48631 CVE-2025-48631: In onHeaderDecoded of LocalImageResolver In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0645P3UNKNOWN≥ 11:0, < 11:2021-08-012021-08-01
CVE-2021-0645 CVE-2021-0645: In shouldBlockFromTree of ExternalStorageProvider In shouldBlockFromTree of ExternalStorageProvider.java, there is a possible permissions bypass. This could lead to local escalation of privilege, allowing an app to read private app directories in external storage, which should be restricted in Android 11, with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-20921P3UNKNOWN≥ 10:0, < 10:2023-01-01≥ 11:0, < 11:2023-01-01+3 more2023-01-01
CVE-2023-20921 CVE-2023-20921: In onPackageRemoved of AccessibilityManagerService In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically grant accessibility services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0954P3UNKNOWN≥ 10:0, < 10:2021-12-01≥ 11:0, < 11:2021-12-012021-12-01
CVE-2021-0954 CVE-2021-0954: In ResolverActivity, there is a possible user interaction bypass due to a tapjacking/overlay attack In ResolverActivity, there is a possible user interaction bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0317P3UNKNOWN≥ 8.0:0, < 8.0:2021-01-01≥ 8.1:0, < 8.1:2021-01-01+3 more2021-01-01
CVE-2021-0317 CVE-2021-0317: In createOrUpdate of Permission In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0438P3UNKNOWN≥ 8.1:0, < 8.1:2021-04-01≥ 9:0, < 9:2021-04-01+1 more2021-04-01
CVE-2021-0438 CVE-2021-0438: In several functions of InputDispatcher In several functions of InputDispatcher.cpp, WindowManagerService.java, and related files, there is a possible tapjacking attack due to an incorrect FLAG_OBSCURED value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39668P3UNKNOWN≥ 11:0, < 11:2022-02-01≥ 12:0, < 12:2022-02-012022-02-01
CVE-2021-39668 CVE-2021-39668: In onActivityViewReady of DetailDialog In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-1021P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1021 CVE-2021-1021: In snoozeNotificationInt of NotificationManagerService In snoozeNotificationInt of NotificationManagerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-1020P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1020 CVE-2021-1020: In snoozeNotification of NotificationListenerService In snoozeNotification of NotificationListenerService.java, there is a possible way to disable notification for an arbitrary user due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-21189P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21189 CVE-2023-21189: In startLockTaskMode of LockTaskController In startLockTaskMode of LockTaskController.java, there is a possible bypass of lock task mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0315P3UNKNOWN≥ 8.0:0, < 8.0:2021-01-01≥ 8.1:0, < 8.1:2021-01-01+3 more2021-01-01
CVE-2021-0315 CVE-2021-0315: In onCreate of GrantCredentialsPermissionActivity In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0314P3UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0314 CVE-2021-0314: In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0319P3UNKNOWN≥ 8.0:0, < 8.0:2021-01-01≥ 8.1:0, < 8.1:2021-01-01+3 more2021-01-01
CVE-2021-0319 CVE-2021-0319: In checkCallerIsSystemOr of CompanionDeviceManagerService In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass. This could lead to local escalation of privilege that grants access to nearby MAC addresses, with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20193P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2022-20193 CVE-2022-20193: In getUniqueUsagesWithLabels of PermissionUsageHelper In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission attribution due to a logic error in the code. This could lead to local escalation of privilege by conflating apps with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0538P3UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0538 CVE-2021-0538: In onCreate of EmergencyCallbackModeExitDialog In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-39691P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 11:0, < 11:2022-06-01+1 more2022-06-01
CVE-2021-39691 CVE-2021-39691: In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-1016P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1016 CVE-2021-1016: In onCreate of UsbPermissionActivity In onCreate of UsbPermissionActivity.java, there is a possible way to grant an app access to USB without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-48545P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48545 CVE-2025-48545: In isSystemUid of AccountManagerService In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a confused deputy. This could lead to local privilege escalation with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Base vulnerabilities | cvebase