Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 17 of 29
CVE-2021-39796P4UNKNOWN≥ 10:0, < 10:2022-04-01≥ 11:0, < 11:2022-04-01+2 more2022-04-01
CVE-2021-39796 CVE-2021-39796: In HarmfulAppWarningActivity of HarmfulAppWarningActivity
In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-48533P4UNKNOWN≥ 16-next:0, < 16-next:2025-08-01≥ 15:0, < 15:2025-08-01+3 more2025-08-01
CVE-2025-48533 CVE-2025-48533: In multiple locations, there is a possible way to use apps linked from a context menu of a lockscreen app due to a race condition
In multiple locations, there is a possible way to use apps linked from a context menu of a lockscreen app due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0044P3UNKNOWN≥ 15-next:0, < 15-next:2024-10-01≥ 12:0, < 12:2024-10-01+3 more2024-10-01
CVE-2024-0044 CVE-2024-0044: In createSessionInternal of PackageInstallerService
In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0041P4UNKNOWN≥ 14-next:0, < 14-next:2024-02-01≥ 14:0, < 14:2024-02-012024-02-01
CVE-2024-0041 CVE-2024-0041: In removePersistentDot of SystemStatusAnimationSchedulerImpl
In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49724P4UNKNOWN≥ 15-next:0, < 15-next:2025-01-01≥ 12:0, < 12:2025-01-01+4 more2025-01-01
CVE-2024-49724 CVE-2024-49724: In multiple functions of AccountManagerService
In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0432P4UNKNOWN≥ 11:0, < 11:2021-04-012021-04-01
CVE-2021-0432 CVE-2021-0432: In ClearPullerCacheIfNecessary and ForceClearPullerCache of StatsPullerManager
In ClearPullerCacheIfNecessary and ForceClearPullerCache of StatsPullerManager.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32319P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 16:0, < 16:2025-12-012025-12-01
CVE-2025-32319 CVE-2025-32319: In ensureBound of RemotePrintService
In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions due to a permissions bypass. This could lead to local escalation of privilege with user execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40076P4UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 14:0, < 14:2023-12-012023-12-01
CVE-2023-40076 CVE-2023-40076: In createPendingIntent of CredentialManagerUi
In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0551P4UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0551 CVE-2021-0551: In bind of MediaControlPanel
In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0969P4UNKNOWN≥ 10:0, < 10:2021-12-01≥ 11:0, < 11:2021-12-012021-12-01
CVE-2021-0969 CVE-2021-0969: In getTitle of AccessPoint
In getTitle of AccessPoint.java, there is a possible unhandled exception due to a missing null check. This could lead to remote denial of service if a proximal Wi-Fi AP provides invalid information with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0688P4UNKNOWN≥ 8.1:0, < 8.1:2021-09-01≥ 9:0, < 9:2021-09-01+2 more2021-09-01
CVE-2021-0688 CVE-2021-0688: In lockNow of PhoneWindowManager
In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48537P4UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48537 CVE-2025-48537: In multiple locations, there is a possible way to persistently DoS the device due to improper input validation
In multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20514P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20514 CVE-2022-20514: In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service
In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0993P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0993 CVE-2021-0993: In getOffsetBeforeAfter of TextLine
In getOffsetBeforeAfter of TextLine.java, there is a possible denial of service due to resource exhaustion. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-0032P4UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 12:0, < 12:2025-03-01+3 more2025-03-01
CVE-2024-0032 CVE-2024-0032: In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation
In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20007P4UNKNOWN≥ 10:0, < 10:2022-05-01≥ 11:0, < 11:2022-05-01+2 more2022-05-01
CVE-2022-20007 CVE-2022-20007: In startActivityForAttachedApplicationIfNeeded of RootWindowContainer
In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's still in the foreground, when it is not, due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-20926P4UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 12:0, < 12:2023-03-01+2 more2023-03-01
CVE-2023-20926 CVE-2023-20926: In onParentVisible of HeaderPrivacyIconsController
In onParentVisible of HeaderPrivacyIconsController.kt, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with physical access to a device that's been factory reset with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2026-0005P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+2 more2026-03-01
CVE-2026-0005 CVE-2026-0005: In onServiceDisconnected of KeyguardServiceDelegate
In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction with other apps without knowing the LSKF due to a missing permission check. This could lead to local information disclosure where the extent of interaction and impact is app-dependent with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20504P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20504 CVE-2022-20504: In multiple locations of DreamManagerService
In multiple locations of DreamManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and dismissal of system dialogs with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0086P4UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 12:0, < 12:2025-03-01+4 more2025-03-01
CVE-2025-0086 CVE-2025-0086: In onResult of AccountManagerService
In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv