Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 5 of 29
CVE-2025-26444P3UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 13:0, < 13:2025-05-01+1 more2025-05-01
CVE-2025-26444 CVE-2025-26444: In onHandleForceStop of VoiceInteractionManagerService
In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly revert to the default assistant application when a user-selected assistant is forcibly stopped due to a logic error in the code. This could lead to local escalation of privilege where the default assistant app is automatically granted ROLE_ASSISTANT with no additional execution privileges neede
osv
CVE-2024-40672P3UNKNOWN≥ 12:0, < 12:2024-10-01≥ 12L:0, < 12L:2024-10-01+1 more2024-10-01
CVE-2024-40672 CVE-2024-40672: In onCreate of ChooserActivity
In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26436P3UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-01+2 more2025-05-01
CVE-2025-26436 CVE-2025-26436: In clearAllowBgActivityStarts of PendingIntentRecord
In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26440P3UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 14:0, < 14:2025-05-012025-05-01
CVE-2025-26440 CVE-2025-26440: In multiple functions of CameraService
In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-23713P3UNKNOWN≥ 14-next:0, < 14-next:2024-04-01≥ 12:0, < 12:2024-04-01+3 more2024-04-01
CVE-2024-23713 CVE-2024-23713: In migrateNotificationFilter of NotificationManagerService
In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48563P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48563 CVE-2025-48563: In onNullBinding of RemoteFillService
In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32350P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+2 more2025-09-01
CVE-2025-32350 CVE-2025-32350: In maybeShowDialog of ControlsSettingsDialogManager
In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26462P3UNKNOWN≥ 16-next:0, < 16-next:2025-06-01≥ 15:0, < 15:2025-06-01+2 more2025-06-01
CVE-2025-26462 CVE-2025-26462: In AccessibilityServiceConnection
In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48558P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48558 CVE-2025-48558: In multiple functions of BatteryService
In multiple functions of BatteryService.java, there is a possible way to hijack implicit intent intended for system app due to Implicit intent hijacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22416P3UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2025-22416 CVE-2025-22416: In onCreate of ChooserActivity
In onCreate of ChooserActivity.java , there is a possible way to view other users' images due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49744P3UNKNOWN≥ 15-next:0, < 15-next:2025-01-01≥ 12:0, < 12:2025-01-01+4 more2025-01-01
CVE-2024-49744 CVE-2024-49744: In checkKeyIntentParceledCorrectly of AccountManagerService
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-48597P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+2 more2025-12-01
CVE-2025-48597 CVE-2025-48597: In multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack
In multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22420P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-22420 CVE-2025-22420: In multiple locations, there is a possible way to leak audio files across user profiles due to a confused deputy
In multiple locations, there is a possible way to leak audio files across user profiles due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0517P3UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0517 CVE-2021-0517: In updateCapabilities of ConnectivityService
In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determination due to a logic error in the code. This could lead to biasing of networking tasks to occur on non-VPN networks, which could lead to remote information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20545P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20545 CVE-2022-20545: In bindArtworkAndColors of MediaControlPanel
In bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0334P3UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0334 CVE-2021-0334: In onTargetSelected of ResolverActivity
In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20474P3UNKNOWN≥ 10:0, < 10:2022-12-01≥ 11:0, < 11:2022-12-01+3 more2022-12-01
CVE-2022-20474 CVE-2022-20474: In readLazyValue of Parcel
In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40115P3UNKNOWN≥ 11:0, < 11:2023-11-012023-11-01
CVE-2023-40115 CVE-2023-40115: In readLogs of StatsService
In readLogs of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43762P3UNKNOWN≥ 15-next:0, < 15-next:2024-12-01≥ 12:0, < 12:2024-12-01+3 more2024-12-01
CVE-2024-43762 CVE-2024-43762: In multiple locations, there is a possible way to avoid unbinding of a service from the system due to a logic error in the code
In multiple locations, there is a possible way to avoid unbinding of a service from the system due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21286P3UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 11:0, < 11:2023-08-01+3 more2023-08-01
CVE-2023-21286 CVE-2023-21286: In visitUris of RemoteViews
In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv