VendorsGoogleandroidall versions
Vulnerabilities

Google Android

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9603CVEs
CVE-2023-20950
In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restrictions via a pendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-195756028
Published 2023-04-19 · Modified
7.8EPSS 0.001
CVE-2025-26430
In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
7.8EPSS 0.001
CVE-2025-22426
In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-06-01 · Modified
7.8EPSS 0.001
CVE-2025-20778
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184870; Issue ID: MSV-4729.
Published 2026-01-06 · Analyzed
7.8EPSS 0.001
CVE-2023-40132
In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Published 2025-01-21 · Modified
7.8EPSS 0.001
CVE-2023-38464
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38453
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38452
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38455
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38451
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38449
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38444
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38456
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38459
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38450
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38458
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38443
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2023-38460
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
Published 2023-09-04 · Modified
7.8EPSS 0.001
CVE-2025-26435
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
7.8EPSS 0.001
CVE-2025-26462
In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
7.8EPSS 0.001
CVE-2022-39883
Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
Published 2022-11-09 · Modified
7.8EPSS 0.001
CVE-2023-21121
In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-205460459
Published 2023-06-15 · Modified
7.8EPSS 0.001
CVE-2025-48652
In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-06-01 · Analyzed
7.8EPSS 0.001
CVE-2025-32322
In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enabling unauthorized screen recording capabilities due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
7.8EPSS 0.001
CVE-2023-35692
In getLocationCache of GeoLocation.java, there is a possible way to send a mock location during an emergency call due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-07-14 · Modified
7.8EPSS 0.001
CVE-2025-22428
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the primary user due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-02 · Analyzed
7.8EPSS 0.001
CVE-2024-56190
In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
7.8EPSS 0.001
CVE-2025-36887
In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
7.8EPSS 0.001
CVE-2025-36903
In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
7.8EPSS 0.001
CVE-2024-23713
In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-05-07 · Analyzed
7.8EPSS 0.001
CVE-2023-21138
In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to local escalation of privilege and background activity launches with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-273260090
Published 2023-06-15 · Modified
7.8EPSS 0.001
CVE-2025-20795
In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10276761; Issue ID: MSV-5141.
Published 2026-01-06 · Analyzed
7.8EPSS 0.001
CVE-2026-0045
In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-06-01 · Analyzed
7.8EPSS 0.001
CVE-2018-9392
In get_binary of vendor/mediatek/proprietary/hardware/connectivity/gps/gps_hal/src/data_coder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published 2024-12-04 · Analyzed
7.8EPSS 0.001
CVE-2018-9393
In procfile_write of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_proc.c, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published 2024-12-04 · Analyzed
7.8EPSS 0.001
CVE-2018-9394
In mtk_p2p_wext_set_key of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_p2p.c, there is a possible OOB write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published 2024-12-04 · Analyzed
7.8EPSS 0.001
CVE-2018-9395
In mtk_cfg80211_vendor_packet_keep_alive_start and mtk_cfg80211_vendor_set_config of drivers/misc/mediatek/connectivity/wlan/gen2/os/linux/gl_vendor.c, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published 2024-12-04 · Analyzed
7.8EPSS 0.001
CVE-2018-9396
In rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published 2024-12-04 · Analyzed
7.8EPSS 0.001
CVE-2018-9397
In WMT_unlocked_ioctl of MTK WMT device driver, there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published 2024-12-04 · Analyzed
7.8EPSS 0.001
CVE-2018-9398
In fm_set_stat of mediatek FM radio driver, there is a possible OOB write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published 2024-12-04 · Analyzed
7.8EPSS 0.001
← Prev106 / 241Next →