Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 19 of 29
CVE-2025-22421P4UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2025-22421 CVE-2025-22421: In contentDescForNotification of NotificationContentDescription
In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification content leak through the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22430P4UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-012025-04-01
CVE-2025-22430 CVE-2025-22430: In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing permission check
In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0082P4UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 12:0, < 12:2025-03-01+4 more2025-03-01
CVE-2025-0082 CVE-2025-0082: In multiple functions of StatusHint
In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-40123P4UNKNOWN≥ 11:0, < 11:2023-10-01≥ 12:0, < 12:2023-10-01+2 more2023-10-01
CVE-2023-40123 CVE-2023-40123: In updateActionViews of PipMenuView
In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21249P4UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 13:0, < 13:2023-07-012023-07-01
CVE-2023-21249 CVE-2023-21249: In multiple functions of OneTimePermissionUserManager
In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40105P4UNKNOWN≥ 14-next:0, < 14-next:2023-11-01≥ 11:0, < 11:2023-11-01+4 more2023-11-01
CVE-2023-40105 CVE-2023-40105: In backupAgentCreated of ActivityManagerService
In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26448P4UNKNOWN≥ 16-next:0, < 16-next:2025-06-01≥ 15:0, < 15:2025-06-01+2 more2025-06-01
CVE-2025-26448 CVE-2025-26448: In writeToParcel of CursorWindow
In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21238P4UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 11:0, < 11:2023-07-01+3 more2023-07-01
CVE-2023-21238 CVE-2023-21238: In visitUris of RemoteViews
In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0294P4UNKNOWN≥ 8.0:0, < 8.0:2020-12-01≥ 8.1:0, < 8.1:2020-12-01+2 more2020-12-01
CVE-2020-0294 CVE-2020-0294: In bindWallpaperComponentLocked of WallpaperManagerService
In bindWallpaperComponentLocked of WallpaperManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21288P4UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 11:0, < 11:2023-08-01+3 more2023-08-01
CVE-2023-21288 CVE-2023-21288: In visitUris of Notification
In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0448P4UNKNOWN≥ 11-next:0, < 11-next:2020-11-012020-11-01
CVE-2020-0448 CVE-2020-0448: In getPhoneAccountsForPackage of TelecomServiceImpl
In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to a missing permission check. This could lead to local information disclosure of the identifier, which could be used to track an account across devices, with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0400P4UNKNOWN≥ 9:0, < 9:2021-04-01≥ 10:0, < 10:2021-04-01+1 more2021-04-01
CVE-2021-0400 CVE-2021-0400: In injectBestLocation and handleUpdateLocation of GnssLocationProvider
In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of location data to emergency services due to improper input validation. This could lead to incorrect reporting of location data to emergency services with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40098P4UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 12:0, < 12:2023-12-01+3 more2023-12-01
CVE-2023-40098 CVE-2023-40098: In mOnDone of NotificationConversationInfo
In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21267P4UNKNOWN≥ 14-next:0, < 14-next:2024-04-01≥ 12:0, < 12:2024-04-01+3 more2024-04-01
CVE-2023-21267 CVE-2023-21267: In multiple functions of KeyguardViewMediator
In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2026-0049P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-04-01≥ 15:0, < 15:2026-04-01+3 more2026-04-01
CVE-2026-0049 CVE-2026-0049: In onHeaderDecoded of LocalImageResolver
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43082P4UNKNOWN≥ 12:0, < 12:2024-11-01≥ 12L:0, < 12L:2024-11-012024-11-01
CVE-2024-43082 CVE-2024-43082: In onActivityResult of EditUserPhotoController
In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26426P4UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-01+2 more2025-05-01
CVE-2025-26426 CVE-2025-26426: In BroadcastController
In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22425P4UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 13:0, < 13:2025-05-01+1 more2025-05-01
CVE-2025-22425 CVE-2025-22425: In onCreate of InstallStart
In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-43084P4UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 12:0, < 12:2024-11-01+3 more2024-11-01
CVE-2024-43084 CVE-2024-43084: In visitUris of multiple files, there is a possible information disclosure due to a confused deputy
In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2026-0014P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+3 more2026-03-01
CVE-2026-0014 CVE-2026-0014: In isPackageNullOrSystem of AppOpsService
In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv