Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 18 of 29
CVE-2021-1024P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1024 CVE-2021-1024: In onEventReceived of EventResultPersister
In onEventReceived of EventResultPersister.java, there is a possible intent redirection due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21116P4UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+3 more2023-05-01
CVE-2023-21116 CVE-2023-21116: In verifyReplacingVersionCode of InstallPackageHelper
In verifyReplacingVersionCode of InstallPackageHelper.java, there is a possible way to downgrade system apps below system image version due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40121P4UNKNOWN≥ 14-next:0, < 14-next:2023-10-01≥ 11:0, < 11:2023-10-01+3 more2023-10-01
CVE-2023-40121 CVE-2023-40121: In appendEscapedSQLString of DatabaseUtils
In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32330P4UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+2 more2025-09-01
CVE-2025-32330 CVE-2025-32330: In generateRandomPassword of LocalBluetoothLeBroadcast
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio stream due to an insecure default value. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2026-0012P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+2 more2026-03-01
CVE-2026-0012 CVE-2026-0012: In setHideSensitive of ExpandableNotificationRow
In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20530P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20530 CVE-2022-20530: In strings
In strings.xml, there is a possible permission bypass due to a misleading string. This could lead to remote information disclosure of call logs with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20553P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20553 CVE-2022-20553: In onCreate of LogAccessDialogActivity
In onCreate of LogAccessDialogActivity.java, there is a possible way to bypass a permission check due to a tapjacking/overlay attack. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-0022P4UNKNOWN≥ 14-next:0, < 14-next:2024-04-01≥ 13:0, < 13:2024-04-01+1 more2024-04-01
CVE-2024-0022 CVE-2024-0022: In multiple functions of CompanionDeviceManagerService
In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another user profile due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48591P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+2 more2025-12-01
CVE-2025-48591 CVE-2025-48591: In multiple locations, there is a possible way to read files from another user due to a missing permission check
In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20909P4UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 11:0, < 11:2023-04-01+3 more2023-04-01
CVE-2023-20909 CVE-2023-20909: In multiple functions of RunningTasks
In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40133P4UNKNOWN≥ 15-next:0, < 15-next:2025-02-01≥ 12:0, < 12:2025-02-01+2 more2025-02-01
CVE-2023-40133 CVE-2023-40133: In multiple locations of DialogFillUi
In multiple locations of DialogFillUi.java, there is a possible way to view another user's image. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21285P4UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 11:0, < 11:2023-08-01+3 more2023-08-01
CVE-2023-21285 CVE-2023-21285: In setMetadata of MediaSessionRecord
In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20457P4UNKNOWN≥ 13:0, < 13:2022-11-012022-11-01
CVE-2022-20457 CVE-2022-20457: In getMountModeInternal of StorageManagerService
In getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40081P4UNKNOWN≥ 14-next:0, < 14-next:2024-03-01≥ 12:0, < 12:2024-03-01+3 more2024-03-01
CVE-2023-40081 CVE-2023-40081: In loadMediaDataInBgForResumption of MediaDataManager
In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40092P4UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 11:0, < 11:2023-12-01+4 more2023-12-01
CVE-2023-40092 CVE-2023-40092: In verifyShortcutInfoPackage of ShortcutService
In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49722P4UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-012025-04-01
CVE-2024-49722 CVE-2024-49722: In showAvatarPicker of EditUserPhotoController
In showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20448P4UNKNOWN≥ 10:0, < 10:2022-11-01≥ 11:0, < 11:2022-11-01+3 more2022-11-01
CVE-2022-20448 CVE-2022-20448: In buzzBeepBlinkLocked of NotificationManagerService
In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35675P4UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 11:0, < 11:2023-09-01+3 more2023-09-01
CVE-2023-35675 CVE-2023-35675: In loadMediaResumptionControls of MediaResumeListener
In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files played by another user on the same device due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0706P4UNKNOWN≥ 10:0, < 10:2022-02-01≥ 11:0, < 11:2022-02-012022-02-01
CVE-2021-0706 CVE-2021-0706: In startListening of PluginManagerImpl
In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31312P4UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 12:0, < 12:2024-06-01+3 more2024-06-01
CVE-2024-31312 CVE-2024-31312: In multiple locations, there is a possible information leak due to a missing permission check
In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local information disclosure exposing played media with no additional execution privileges needed. User interaction is not needed for exploitation.
osv