VendorsGoogleandroid16.0
Vulnerabilities

Google Android 16.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

369CVEs
CVE-2026-28586
In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-06-01 · Analyzed
3.3EPSS 0.001
CVE-2026-28582
In onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unauthorized access to and modification of device credentials due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
3.3EPSS 0.001
CVE-2026-28623
In writeToParcel of BleRssiRangingCapabilities.java, there is a possible way to obtain the Bluetooth MAC address due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
3.3EPSS 0.001
CVE-2025-26461
In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the user attempts to close the app due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-05 · Analyzed
3.3EPSS 0.001
CVE-2026-28671
In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
3.3EPSS 0.001
CVE-2026-0050
In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-06-01 · Analyzed
3.3EPSS 0.001
CVE-2026-0016
In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-06-01 · Analyzed
3.3EPSS 0.001
CVE-2026-0054
In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
3.3EPSS 0.001
CVE-2026-28652
In multiple functions of RangingServiceImpl.java, there is a possible MITM due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
3.1EPSS 0.002
← Prev10 / 10