cbcvebase.

Platform Frameworks Base vulnerabilities

579 known vulnerabilities affecting platform/frameworks_base.

Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579

Vulnerabilities

Page 4 of 29
CVE-2024-23708P3UNKNOWN≥ 14-next:0, < 14-next:2024-05-01≥ 12:0, < 12:2024-05-01+3 more2024-05-01
CVE-2024-23708 CVE-2024-23708: In multiple functions of NotificationManagerService In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31320P3UNKNOWN≥ 12:0, < 12:2024-07-01≥ 12L:0, < 12L:2024-07-012024-07-01
CVE-2024-31320 CVE-2024-31320: In setSkipPrompt of AssociationRequest In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20142P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 10:0, < 10:2022-06-01+3 more2022-06-01
CVE-2022-20142 CVE-2022-20142: In createFromParcel of GeofenceHardwareRequestParcelable In createFromParcel of GeofenceHardwareRequestParcelable.java, there is a possible arbitrary code execution due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21097P3UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 11:0, < 11:2023-04-01+3 more2023-04-01
CVE-2023-21097 CVE-2023-21097: In toUriInner of Intent In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40676P3UNKNOWN≥ 15-next:0, < 15-next:2024-10-01≥ 12:0, < 12:2024-10-01+3 more2024-10-01
CVE-2024-40676 CVE-2024-40676: In checkKeyIntent of AccountManagerService In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-34741P3UNKNOWN≥ 14-next:0, < 14-next:2024-08-01≥ 12:0, < 12:2024-08-01+3 more2024-08-01
CVE-2024-34741 CVE-2024-34741: In setForceHideNonSystemOverlayWindowIfNeeded of WindowState In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted by the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0029P3UNKNOWN≥ 13:0, < 13:2024-02-012024-02-01
CVE-2024-0029 CVE-2024-0029: In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31326P3UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 14:0, < 14:2024-06-012024-06-01
CVE-2024-31326 CVE-2024-31326: In multiple locations, there is a possible way in which policy migration code will never be executed due to a logic error in the code In multiple locations, there is a possible way in which policy migration code will never be executed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0036P3UNKNOWN≥ 14-next:0, < 14-next:2024-02-01≥ 11:0, < 11:2024-02-01+4 more2024-02-01
CVE-2024-0036 CVE-2024-0036: In startNextMatchingActivity of ActivityTaskManagerService In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43085P3UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 12:0, < 12:2024-11-01+4 more2024-11-01
CVE-2024-43085 CVE-2024-43085: In handleMessage of UsbDeviceManager In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31318P3UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 12:0, < 12:2024-06-01+3 more2024-06-01
CVE-2024-31318 CVE-2024-31318: In CompanionDeviceManagerService In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43081P3UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 12:0, < 12:2024-11-01+3 more2024-11-01
CVE-2024-43081 CVE-2024-43081: In installExistingPackageAsUser of InstallPackageHelper In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0089P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+2 more2025-09-01
CVE-2025-0089 CVE-2025-0089: In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48522P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48522 CVE-2025-48522: In setDisplayName of AssociationRequest In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40120P3UNKNOWN≥ 14-next:0, < 14-next:2023-10-01≥ 11:0, < 11:2023-10-01+3 more2023-10-01
CVE-2023-40120 CVE-2023-40120: In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0080P3UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 15:0, < 15:2025-03-012025-03-01
CVE-2025-0080 CVE-2025-0080: In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overlay attack In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-23710P3UNKNOWN≥ 14-next:0, < 14-next:2024-04-01≥ 13:0, < 13:2024-04-01+1 more2024-04-01
CVE-2024-23710 CVE-2024-23710: In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48589P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48589 CVE-2025-48589: In multiple functions of HeaderPrivacyIconsController In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32349P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-32349 CVE-2025-32349: In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48546P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48546 CVE-2025-48546: In checkPermissions of SafeActivityOptions In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Base vulnerabilities | cvebase