VendorsGoogleandroidall versions
Vulnerabilities

Google Android

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9581CVEs
CVE-2025-0074
In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-08-26 · Analyzed
9.8EPSS 0.004
CVE-2022-23425
Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.
Published 2022-02-11 · Modified
9.8EPSS 0.004
CVE-2022-20122
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid ID: A-232441339
Published 2022-08-24 · Modified
9.8EPSS 0.004
CVE-2021-39815
The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid ID: A-232440670
Published 2022-08-24 · Modified
9.8EPSS 0.004
CVE-2020-10849
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock password. The Samsung ID is SVE-2019-14575 (January 2020).
Published 2020-03-24 · Modified
9.8EPSS 0.004
CVE-2020-13835
An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).
Published 2020-06-04 · Modified
9.8EPSS 0.004
CVE-2026-56960
In multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-15 · Analyzed
9.8EPSS 0.004
CVE-2019-20576
An issue was discovered on Samsung mobile devices with P(9.0) software. The MemorySaver Content Provider allows SQL injection. The Samsung ID is SVE-2019-14365 (August 2019).
Published 2020-03-24 · Modified
9.8EPSS 0.004
CVE-2023-21216
In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
9.8EPSS 0.004
CVE-2018-9341
In impeg2d_mc_fullx_fully of impeg2d_mc.c there is a possible out of bound write due to missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.
Published 2024-11-19 · Analyzed
9.8EPSS 0.004
CVE-2018-9430
In prop2cfg of btif_storage.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-12-02 · Analyzed
9.8EPSS 0.004
CVE-2021-25449
An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers to execute arbitrary code in mediaextractor process.
Published 2021-09-09 · Modified
9.8EPSS 0.004
CVE-2025-22408
In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-08-26 · Analyzed
9.8EPSS 0.004
CVE-2025-22403
In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-08-26 · Analyzed
9.8EPSS 0.004
CVE-2026-28606
In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
9.8EPSS 0.004
CVE-2026-49921
In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
9.8EPSS 0.004
CVE-2022-20402
Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2022-20403
Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2018-9478
In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.  User interaction is not needed for exploitation.
Published 2024-11-20 · Analyzed
9.8EPSS 0.004
CVE-2018-9479
In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.  User interaction is not needed for exploitation.
Published 2024-11-20 · Analyzed
9.8EPSS 0.004
CVE-2026-58822
In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
9.8EPSS 0.004
CVE-2026-0163
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-08-04 · Analyzed
9.8EPSS 0.004
CVE-2025-48626
In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-12-08 · Modified
9.8EPSS 0.004
CVE-2022-20365
Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2022-20378
Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2021-0942
The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC this crashes as an OOB read. However, given that the OOB read value is ending up as the address field of a struct I think i seems plausible that this could lead to an OOB write if the attacker is able to cause the OOB read to pull an interesting kernel address. Regardless if this is a read or write, it is a High severity issue in the kernel.Product: AndroidVersions: Android SoCAndroid ID: A-238904312
Published 2022-09-13 · Modified
9.8EPSS 0.004
CVE-2025-26416
In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-02 · Analyzed
9.8EPSS 0.004
CVE-2022-33719
Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.
Published 2022-08-05 · Modified
9.8EPSS 0.004
CVE-2022-20405
Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2022-20384
Product: AndroidVersions: Android kernelAndroid ID: A-211727306References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2022-20381
Product: AndroidVersions: Android kernelAndroid ID: A-188935887References: N/A
Published 2022-08-11 · Modified
9.8EPSS 0.004
CVE-2024-23708
In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-05-07 · Analyzed
9.8EPSS 0.003
CVE-2026-30793
RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation
Published 2026-03-05 · Analyzed
9.8EPSS 0.003
CVE-2021-26277
Security Advisory | PendingIntent hijacking vulnerability in Framework Services
Published 2023-02-17 · Modified
9.8EPSS 0.003
CVE-2023-35647
In ProtocolEmbmsGlobalCellIdAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
Published 2023-10-11 · Modified
9.8EPSS 0.003
CVE-2023-35648
In ProtocolMiscLceIndAdapter::GetConfLevel() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
Published 2023-10-11 · Modified
9.8EPSS 0.003
CVE-2024-53842
In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-01-03 · Analyzed
9.8EPSS 0.003
CVE-2024-20103
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001358; Issue ID: MSV-1599.
Published 2024-10-07 · Analyzed
9.8EPSS 0.003
CVE-2024-20100
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Issue ID: MSV-1603.
Published 2024-10-07 · Analyzed
9.8EPSS 0.003
CVE-2026-30789
RustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force
Published 2026-03-05 · Modified
9.8EPSS 0.003
← Prev23 / 240Next →