Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 22 of 29
CVE-2023-21276P4UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 12:0, < 12:2023-08-01+2 more2023-08-01
CVE-2023-21276 CVE-2023-21276: In writeToParcel of CursorWindow
In writeToParcel of CursorWindow.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21239P4UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 12:0, < 12:2023-07-01+2 more2023-07-01
CVE-2023-21239 CVE-2023-21239: In visitUris of Notification
In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20352P4UNKNOWN≥ 12:0, < 12:2022-08-01≥ 12L:0, < 12L:2022-08-012022-08-01
CVE-2022-20352 CVE-2022-20352: In addProviderRequestListener of LocationManagerService
In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request location information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21143P4UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21143 CVE-2023-21143: In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation
In multiple functions of multiple files, there is a possible way to make the device unusable due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21142P4UNKNOWN≥ 12:0, < 12:2023-06-01≥ 12L:0, < 12L:2023-06-012023-06-01
CVE-2023-21142 CVE-2023-21142: In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass
In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21104P4UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 12L:0, < 12L:2023-05-01+1 more2023-05-01
CVE-2023-21104 CVE-2023-21104: In applySyncTransaction of WindowOrganizer
In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26463P4UNKNOWN≥ 16-next:0, < 16-next:2025-06-01≥ 15:0, < 15:2025-06-01+2 more2025-06-01
CVE-2025-26463 CVE-2025-26463: In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages
In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This could lead to a local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48576P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48576 CVE-2025-48576: In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService
In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-34742P4UNKNOWN≥ 14-next:0, < 14-next:2024-08-01≥ 14:0, < 14:2024-08-012024-08-01
CVE-2024-34742 CVE-2024-34742: In shouldWrite of OwnersData
In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22431P4UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2025-22431 CVE-2025-22431: In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logic
In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logic error in the code. This could lead to local denial of service until the phone reboots with no additional execution privileges needed. User interaction is not needed fo
osv
CVE-2025-48607P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+1 more2025-12-01
CVE-2025-48607 CVE-2025-48607: In multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code
In multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20219P4UNKNOWN≥ 10:0, < 10:2022-07-01≥ 11:0, < 11:2022-07-01+2 more2022-07-01
CVE-2022-20219 CVE-2022-20219: In multiple functions of StorageManagerService
In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48601P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48601 CVE-2025-48601: In multiple locations, there is a possible permanent denial of service due to improper input validation
In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0480P4UNKNOWN≥ 8.1:0, < 8.1:2021-05-01≥ 9:0, < 9:2021-05-01+2 more2021-05-01
CVE-2021-0480 CVE-2021-0480: In createPendingIntent of SnoozeHelper
In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensitive identifier. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0258P4UNKNOWN≥ 10:0, < 10:2020-08-012020-08-01
CVE-2020-0258 CVE-2020-0258: In stopZygoteLocked of AppZygote
In stopZygoteLocked of AppZygote.java, there is an insufficient cleanup. This could lead to local information disclosure in the application that is started next with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0239P4UNKNOWN≥ 9:0, < 9:2020-08-01≥ 10:0, < 10:2020-08-012020-08-01
CVE-2020-0239 CVE-2020-0239: In getDocumentMetadata of DocumentsContract
In getDocumentMetadata of DocumentsContract.java, there is a possible disclosure of location metadata from a file due to a permissions bypass. This could lead to local information disclosure from a file (eg. a photo) containing location metadata with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0248P4UNKNOWN≥ 10:0, < 10:2020-08-012020-08-01
CVE-2020-0248 CVE-2020-0248: In postInstantAppNotif of InstantAppNotifier
In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21284P4UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 11:0, < 11:2023-08-01+3 more2023-08-01
CVE-2023-21284 CVE-2023-21284: In multiple functions of DevicePolicyManager
In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43090P4UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 12:0, < 12:2025-03-01+4 more2025-03-01
CVE-2024-43090 CVE-2024-43090: In multiple locations, there is a possible cross-user image read due to a missing permission check
In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20482P4UNKNOWN≥ 12:0, < 12:2022-12-01≥ 12L:0, < 12L:2022-12-01+1 more2022-12-01
CVE-2022-20482 CVE-2022-20482: In createNotificationChannel of NotificationManager
In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv