Platform Frameworks Native vulnerabilities
50 known vulnerabilities affecting platform/frameworks_native.
Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN50
Vulnerabilities
Page 1 of 3
CVE-2025-0078P3UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 12:0, < 12:2025-03-01+4 more2025-03-01
CVE-2025-0078 CVE-2025-0078: In main of main
In main of main.cpp, there is a possible way to bypass SELinux due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32313P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+1 more2026-03-01
CVE-2025-32313 CVE-2025-32313: In UsageEvents of UsageEvents
In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2026-0007P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+2 more2026-03-01
CVE-2026-0007 CVE-2026-0007: In writeToParcel of WindowInfo
In writeToParcel of WindowInfo.cpp, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32325P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-32325 CVE-2025-32325: In appendFrom of Parcel
In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48596P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48596 CVE-2025-48596: In appendFrom of Parcel
In appendFrom of Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48540P3UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48540 CVE-2025-48540: In processTransactInternal of RpcState
In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22438P3UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 13:0, < 13:2025-04-01+1 more2025-04-01
CVE-2025-22438 CVE-2025-22438: In afterKeyEventLockedInterruptable of InputDispatcher
In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20540P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20540 CVE-2022-20540: In SurfaceFlinger::doDump of SurfaceFlinger
In SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0438P3UNKNOWN≥ 11-next:0, < 11-next:2020-11-01≥ 10:0, < 10:2020-11-01+1 more2020-11-01
CVE-2020-0438 CVE-2020-0438: In the AIBinder_Class constructor of ibinder
In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data. This could lead to local escalation of privilege if a process were using libbinder_ndk in a vulnerable way with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0033P3UNKNOWN≥ 14-next:0, < 14-next:2024-02-01≥ 13:0, < 13:2024-02-01+1 more2024-02-01
CVE-2024-0033 CVE-2024-0033: In multiple functions of ashmem-dev
In multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2019-2194P3UNKNOWN≥ 9:0, < 9:2020-10-012020-10-01
CVE-2019-2194 CVE-2019-2194: In SurfaceFlinger::createLayer of SurfaceFlinger
In SurfaceFlinger::createLayer of SurfaceFlinger.cpp, there is a possible arbitrary code execution due to improper casting. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40660P3UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 15:0, < 15:2024-11-01+1 more2024-11-01
CVE-2024-40660 CVE-2024-40660: In setTransactionState of SurfaceFlinger
In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1027P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1027 CVE-2021-1027: In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged process due to improper casting
In setTransactionState of SurfaceFlinger, there is possible arbitrary code execution in a privileged process due to improper casting. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-34743P3UNKNOWN≥ 14-next:0, < 14-next:2024-08-01≥ 14:0, < 14:2024-08-012024-08-01
CVE-2024-34743 CVE-2024-34743: In setTransactionState of SurfaceFlinger
In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49745P3UNKNOWN≥ 15-next:0, < 15-next:2025-01-01≥ 12:0, < 12:2025-01-01+4 more2025-01-01
CVE-2024-49745 CVE-2024-49745: In growData of Parcel
In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-49738P3UNKNOWN≥ 15-next:0, < 15-next:2025-01-01≥ 12:0, < 12:2025-01-01+4 more2025-01-01
CVE-2024-49738 CVE-2024-49738: In writeInplace of Parcel
In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40096P3UNKNOWN≥ 14-next:0, < 14-next:2023-12-01≥ 12:0, < 12:2023-12-01+2 more2023-12-01
CVE-2023-40096 CVE-2023-40096: In OpRecordAudioMonitor::onFirstRef of AudioRecordClient
In OpRecordAudioMonitor::onFirstRef of AudioRecordClient.cpp, there is a possible way to record audio from the background due to a missing flag. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21094P3UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 11:0, < 11:2023-04-01+3 more2023-04-01
CVE-2023-21094 CVE-2023-21094: In sanitize of LayerState
In sanitize of LayerState.cpp, there is a possible way to take over the screen display and swap the display content due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48621P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48621 CVE-2025-48621: In DefaultTransitionHandler
In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-48630P3UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+3 more2026-03-01
CVE-2025-48630 CVE-2025-48630: In drawLayersInternal of SkiaRenderEngine
In drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
1 / 3Next →