cbcvebase.

Platform Frameworks Base vulnerabilities

579 known vulnerabilities affecting platform/frameworks_base.

Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579

Vulnerabilities

Page 27 of 29
CVE-2020-0338P4UNKNOWN≥ 9:0, < 9:2022-01-01≥ 10:0, < 10:2022-01-012022-01-01
CVE-2020-0338 CVE-2020-0338: In checkKeyIntent of AccountManagerService In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0443P4UNKNOWN≥ 8.1:0, < 8.1:2021-04-01≥ 9:0, < 9:2021-04-01+2 more2021-04-01
CVE-2021-0443 CVE-2021-0443: In several functions of ScreenshotHelper In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly saved screenshot due to a race condition. This could lead to local information disclosure across user profiles with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-26427P4UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 13:0, < 13:2025-05-01+1 more2025-05-01
CVE-2025-26427 CVE-2025-26427: In multiple locations, there is a possible Android/data access due to a path traversal error In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-48526P4UNKNOWN≥ 13:0, < 13:2025-09-012025-09-01
CVE-2025-48526 CVE-2025-48526: In createMultiProfilePagerAdapter of ChooserActivity In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActivity in another profile due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0687P4UNKNOWN≥ 8.1:0, < 8.1:2021-09-01≥ 9:0, < 9:2021-09-01+2 more2021-09-01
CVE-2021-0687 CVE-2021-0687: In ellipsize of Layout In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-48614P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48614 CVE-2025-48614: In rebootWipeUserData of RecoverySystem In rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due to a missing permission check. This could lead to physical denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26421P4UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-01+2 more2025-05-01
CVE-2025-26421 CVE-2025-26421: In multiple locations, there is a possible lock screen bypass due to a logic error in the code In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21090P4UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 13:0, < 13:2023-04-012023-04-01
CVE-2023-21090 CVE-2023-21090: In parseUsesPermission of ParsingPackageUtils In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-26422P4UNKNOWN≥ 15:0, < 15:2025-05-012025-05-01
CVE-2025-26422 CVE-2025-26422: In dump of WindowManagerService In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20497P4UNKNOWN≥ 12:0, < 12:2022-12-01≥ 12L:0, < 12L:2022-12-01+1 more2022-12-01
CVE-2022-20497 CVE-2022-20497: In updatePublicMode of NotificationLockscreenUserManagerImpl In updatePublicMode of NotificationLockscreenUserManagerImpl.java, there is a possible way to reveal sensitive notifications on the lockscreen due to an incorrect state transition. This could lead to local information disclosure with physical access required and an app that runs above the lockscreen, with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0077P4UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-012025-05-01
CVE-2025-0077 CVE-2025-0077: In multiple functions of UserController In multiple functions of UserController.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48528P4UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+1 more2025-09-01
CVE-2025-48528 CVE-2025-48528: In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0590P4UNKNOWN≥ 8.1:0, < 8.1:2021-07-01≥ 9:0, < 9:2021-07-01+1 more2021-07-01
CVE-2021-0590 CVE-2021-0590: In sendNetworkConditionsBroadcast of NetworkMonitor In sendNetworkConditionsBroadcast of NetworkMonitor.java, there is a possible way for a privileged app to receive WiFi BSSID and SSID without location permissions due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0083P4UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 12:0, < 12:2025-03-01+4 more2025-03-01
CVE-2025-0083 CVE-2025-0083: In multiple locations, there is a possible way to access content across user profiles due to URI double encoding In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26424P4UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-012025-05-01
CVE-2025-26424 CVE-2025-26424: In multiple functions of VpnManager In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20449P4UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+2 more2022-12-01
CVE-2022-20449 CVE-2022-20449: In writeApplicationRestrictionsLAr of UserManagerService In writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of system files due to a path traversal error. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0958P4UNKNOWN≥ 11:0, < 11:2021-12-012021-12-01
CVE-2021-0958 CVE-2021-0958: In update of km_compat In update of km_compat.cpp, there is a possible loss of potentially sensitive data due to a logic error in the code. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20226P4UNKNOWN≥ 12:0, < 12:2022-07-01≥ 12L:0, < 12L:2022-07-012022-07-01
CVE-2022-20226 CVE-2022-20226: In finishDrawingWindow of WindowManagerService In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20338P4UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+2 more2023-05-01
CVE-2022-20338 CVE-2022-20338: In HierarchicalUri In HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to a local escalation of privilege, preventing processes from validating URIs correctly, with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21246P4UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 11:0, < 11:2023-07-01+3 more2023-07-01
CVE-2023-21246 CVE-2023-21246: In ShortcutInfo of ShortcutInfo In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Base vulnerabilities | cvebase