Platform Frameworks Base vulnerabilities
579 known vulnerabilities affecting platform/frameworks_base.
Total CVEs
579
CISA KEV
7
actively exploited
Public exploits
1
Exploited in wild
7
Severity breakdown
UNKNOWN579
Vulnerabilities
Page 8 of 29
CVE-2020-0074P3UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0074 CVE-2020-0074: In verifyIntentFiltersIfNeeded of PackageManagerService
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20138P3UNKNOWN≥ 10:0, < 10:2022-06-01≥ 11:0, < 11:2022-06-01+2 more2022-06-01
CVE-2022-20138 CVE-2022-20138: In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService
In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVISIONED intent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40096P3UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 12:0, < 12:2023-12-01+2 more2023-12-01
CVE-2023-40096 CVE-2023-40096: In OpRecordAudioMonitor::onFirstRef of AudioRecordClient
In OpRecordAudioMonitor::onFirstRef of AudioRecordClient.cpp, there is a possible way to record audio from the background due to a missing flag. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20944P3UNKNOWN≥ 10:0, < 10:2023-02-01≥ 11:0, < 11:2023-02-01+3 more2023-02-01
CVE-2023-20944 CVE-2023-20944: In run of ChooseTypeAndAccountActivity
In run of ChooseTypeAndAccountActivity.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39704P3UNKNOWN≥ 11:0, < 11:2022-03-01≥ 12:0, < 12:2022-03-01+1 more2022-03-01
CVE-2021-39704 CVE-2021-39704: In deleteNotificationChannelGroup of NotificationManagerService
In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run foreground service without user notification due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21281P3UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 11:0, < 11:2023-08-01+3 more2023-08-01
CVE-2023-21281 CVE-2023-21281: In multiple functions of KeyguardViewMediator
In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen timeout due to a logic error in the code. This could lead to local escalation of privilege across users with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20943P3UNKNOWN≥ 10:0, < 10:2023-02-01≥ 11:0, < 11:2023-02-01+3 more2023-02-01
CVE-2023-20943 CVE-2023-20943: In clearApplicationUserData of ActivityManagerService
In clearApplicationUserData of ActivityManagerService.java, there is a possible way to remove system files due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0307P3UNKNOWN≥ 10:0, < 10:2021-01-01≥ 11:0, < 11:2021-01-012021-01-01
CVE-2021-0307 CVE-2021-0307: In updatePermissionSourcePackage of PermissionManagerService
In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission grant due to a confused deputy. This could lead to local escalation of privilege allowing a malicious app to silently gain access to a dangerous permission with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21109P3UNKNOWN≥ 13-next:0, < 13-next:2023-05-01≥ 11:0, < 11:2023-05-01+3 more2023-05-01
CVE-2023-21109 CVE-2023-21109: In multiple places of AccessibilityService, there is a possible way to hide the app from the user due to a logic error in the code
In multiple places of AccessibilityService, there is a possible way to hide the app from the user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20916P3UNKNOWN≥ 12:0, < 12:2023-01-01≥ 12L:0, < 12L:2023-01-012023-01-01
CVE-2023-20916 CVE-2023-20916: In getMainActivityLaunchIntent of LauncherAppsService
In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48621P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48621 CVE-2025-48621: In DefaultTransitionHandler
In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20550P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20550 CVE-2022-20550: In Multiple Locations, there is a possibility to launch arbitrary protected activities due to a confused deputy
In Multiple Locations, there is a possibility to launch arbitrary protected activities due to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0427P3UNKNOWN≥ 11:0, < 11:2021-04-012021-04-01
CVE-2021-0427 CVE-2021-0427: In parseExclusiveStateAnnotation of LogEvent
In parseExclusiveStateAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0426P3UNKNOWN≥ 11:0, < 11:2021-04-012021-04-01
CVE-2021-0426 CVE-2021-0426: In parsePrimaryFieldFirstUidAnnotation of LogEvent
In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21351P3UNKNOWN≥ 12:0, < 12:2024-08-01≥ 12L:0, < 12L:2024-08-01+1 more2024-08-01
CVE-2023-21351 CVE-2023-21351: In multiple locations, there is a possible background activity launch due to a logic error in the code
In multiple locations, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31310P3UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 12:0, < 12:2024-06-01+3 more2024-06-01
CVE-2024-31310 CVE-2024-31310: In newServiceInfoLocked of AutofillManagerServiceImpl
In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill service settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20420P3UNKNOWN≥ 13:0, < 13:2022-10-012022-10-01
CVE-2022-20420 CVE-2022-20420: In getBackgroundRestrictionExemptionReason of AppRestrictionController
In getBackgroundRestrictionExemptionReason of AppRestrictionController.java, there is a possible way to bypass device policy restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-31322P3UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 12:0, < 12:2024-06-01+3 more2024-06-01
CVE-2024-31322 CVE-2024-31322: In updateServicesLocked of AccessibilityManagerService
In updateServicesLocked of AccessibilityManagerService.java, there is a possible way for an app to be hidden from the Setting while retaining Accessibility Service due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-21191P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21191 CVE-2023-21191: In fixNotification of NotificationManagerService
In fixNotification of NotificationManagerService.java, there is a possible bypass of notification hide preference due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35669P3UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 11:0, < 11:2023-09-01+3 more2023-09-01
CVE-2023-35669 CVE-2023-35669: In checkKeyIntentParceledCorrectly of AccountManagerService
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv