Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 4 of 29
CVE-2024-23708P3UNKNOWN≥ 14-next:0, < 14-next:2024-05-01≥ 12:0, < 12:2024-05-01+3 more2024-05-01
CVE-2024-23708 CVE-2024-23708: In multiple functions of NotificationManagerService
In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31320P3UNKNOWN≥ 12:0, < 12:2024-07-01≥ 12L:0, < 12L:2024-07-012024-07-01
CVE-2024-31320 CVE-2024-31320: In setSkipPrompt of AssociationRequest
In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20142P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 10:0, < 10:2022-06-01+3 more2022-06-01
CVE-2022-20142 CVE-2022-20142: In createFromParcel of GeofenceHardwareRequestParcelable
In createFromParcel of GeofenceHardwareRequestParcelable.java, there is a possible arbitrary code execution due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21097P3UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 11:0, < 11:2023-04-01+3 more2023-04-01
CVE-2023-21097 CVE-2023-21097: In toUriInner of Intent
In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40676P3UNKNOWN≥ 15-next:0, < 15-next:2024-10-01≥ 12:0, < 12:2024-10-01+3 more2024-10-01
CVE-2024-40676 CVE-2024-40676: In checkKeyIntent of AccountManagerService
In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-34741P3UNKNOWN≥ 14-next:0, < 14-next:2024-08-01≥ 12:0, < 12:2024-08-01+3 more2024-08-01
CVE-2024-34741 CVE-2024-34741: In setForceHideNonSystemOverlayWindowIfNeeded of WindowState
In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while lock screen visibility settings are restricted by the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0029P3UNKNOWN≥ 13:0, < 13:2024-02-012024-02-01
CVE-2024-0029 CVE-2024-0029: In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code
In multiple files, there is a possible way to capture the device screen when disallowed by device policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31326P3UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 14:0, < 14:2024-06-012024-06-01
CVE-2024-31326 CVE-2024-31326: In multiple locations, there is a possible way in which policy migration code will never be executed due to a logic error in the code
In multiple locations, there is a possible way in which policy migration code will never be executed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0036P3UNKNOWN≥ 14-next:0, < 14-next:2024-02-01≥ 11:0, < 11:2024-02-01+4 more2024-02-01
CVE-2024-0036 CVE-2024-0036: In startNextMatchingActivity of ActivityTaskManagerService
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43085P3UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 12:0, < 12:2024-11-01+4 more2024-11-01
CVE-2024-43085 CVE-2024-43085: In handleMessage of UsbDeviceManager
In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31318P3UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 12:0, < 12:2024-06-01+3 more2024-06-01
CVE-2024-31318 CVE-2024-31318: In CompanionDeviceManagerService
In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43081P3UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 12:0, < 12:2024-11-01+3 more2024-11-01
CVE-2024-43081 CVE-2024-43081: In installExistingPackageAsUser of InstallPackageHelper
In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0089P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+2 more2025-09-01
CVE-2025-0089 CVE-2025-0089: In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code
In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48522P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48522 CVE-2025-48522: In setDisplayName of AssociationRequest
In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40120P3UNKNOWN≥ 14-next:0, < 14-next:2023-10-01≥ 11:0, < 11:2023-10-01+3 more2023-10-01
CVE-2023-40120 CVE-2023-40120: In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation
In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-0080P3UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 15:0, < 15:2025-03-012025-03-01
CVE-2025-0080 CVE-2025-0080: In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overlay attack
In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-23710P3UNKNOWN≥ 14-next:0, < 14-next:2024-04-01≥ 13:0, < 13:2024-04-01+1 more2024-04-01
CVE-2024-23710 CVE-2024-23710: In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper
In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48589P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48589 CVE-2025-48589: In multiple functions of HeaderPrivacyIconsController
In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32349P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-32349 CVE-2025-32349: In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack
In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48546P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48546 CVE-2025-48546: In checkPermissions of SafeActivityOptions
In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv