cbcvebase.

Platform Frameworks Base vulnerabilities

579 known vulnerabilities affecting platform/frameworks_base.

Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579

Vulnerabilities

Page 7 of 29
CVE-2023-21098P3UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 11:0, < 11:2023-04-01+3 more2023-04-01
CVE-2023-21098 CVE-2023-21098: In multiple functions of AccountManagerService In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2026-0026P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 14:0, < 14:2026-03-012026-03-01
CVE-2026-0026 CVE-2026-0026: In removePermission of PermissionManagerServiceImpl In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any system permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-48646P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+3 more2026-03-01
CVE-2025-48646 CVE-2025-48646: In executeRequest of ActivityStarter In executeRequest of ActivityStarter.java, there is a possible launch anywhere due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-34737P3UNKNOWN≥ 14-next:0, < 14-next:2024-08-01≥ 12:0, < 12:2024-08-01+3 more2024-08-01
CVE-2024-34737 CVE-2024-34737: In ensureSetPipAspectRatioQuotaTracker of ActivityClientController In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21145P3UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 11:0, < 11:2023-07-01+3 more2023-07-01
CVE-2023-21145 CVE-2023-21145: In updatePictureInPictureMode of ActivityRecord In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21131P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 11:0, < 11:2023-06-01+3 more2023-06-01
CVE-2023-21131 CVE-2023-21131: In checkKeyIntentParceledCorrectly() of ActivityManagerService In checkKeyIntentParceledCorrectly() of ActivityManagerService.java, there is a possible bypass of Parcel Mismatch mitigations due to a logic error in the code. This could lead to local escalation of privilege and the ability to launch arbitrary activities in settings with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-34734P3UNKNOWN≥ 14-next:0, < 14-next:2024-08-01≥ 13:0, < 13:2024-08-01+1 more2024-08-01
CVE-2024-34734 CVE-2024-34734: In onForegroundServiceButtonClicked of FooterActionsViewModel In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21126P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21126 CVE-2023-21126: In bindOutputSwitcherAndBroadcastButton of MediaControlPanel In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40106P3UNKNOWN≥ 11:0, < 11:2023-11-01≥ 12:0, < 12:2023-11-01+3 more2023-11-01
CVE-2023-40106 CVE-2023-40106: In sanitizeSbn of NotificationManagerService In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21269P3UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 13:0, < 13:2023-08-012023-08-01
CVE-2023-21269 CVE-2023-21269: In startActivityInner of ActivityStarter In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21117P3UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 13:0, < 13:2023-05-012023-05-01
CVE-2023-21117 CVE-2023-21117: In registerReceiverWithFeature of ActivityManagerService In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to register a broadcast receiver due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21139P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21139 CVE-2023-21139: In bindPlayer of MediaControlPanel In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due to Unsafe Intent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-34738P3UNKNOWN≥ 14-next:0, < 14-next:2024-08-01≥ 13:0, < 13:2024-08-01+1 more2024-08-01
CVE-2024-34738 CVE-2024-34738: In multiple functions of AppOpsService In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21270P3UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 12:0, < 12:2023-08-01+2 more2023-08-01
CVE-2023-21270 CVE-2023-21270: In restorePermissionState of PermissionManagerServiceImpl In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revoked due to incorrect permission flags cleared during an update. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48594P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+2 more2025-12-01
CVE-2025-48594 CVE-2025-48594: In onUidImportance of DisassociationProcessor In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-43769P3UNKNOWN≥ 15-next:0, < 15-next:2024-12-01≥ 13:0, < 13:2024-12-01+1 more2024-12-01
CVE-2024-43769 CVE-2024-43769: In isPackageDeviceAdmin of PackageManagerService In isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48577P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+2 more2026-03-01
CVE-2025-48577 CVE-2025-48577: In multiple functions of KeyguardViewMediator In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48568P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+1 more2026-03-01
CVE-2025-48568 CVE-2025-48568: In multiple locations, there is a possible lockscreen bypass due to a race condition In multiple locations, there is a possible lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49732P3UNKNOWN≥ 15-next:0, < 15-next:2025-01-01≥ 15:0, < 15:2025-01-012025-01-01
CVE-2024-49732 CVE-2024-49732: In multiple functions of CompanionDeviceManagerService In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0705P3UNKNOWN≥ 12-next:0, < 12-next:2021-10-01≥ 10:0, < 10:2021-10-01+2 more2021-10-01
CVE-2021-0705 CVE-2021-0705: In sanitizeSbn of NotificationManagerService In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and keep granted permissions due to Bypass of Background Service Restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Frameworks Base vulnerabilities | cvebase