VendorsGoogleandroid12.0
Vulnerabilities

Google Android 12.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1915CVEs
CVE-2022-36868
Improper restriction of broadcasting Intent in MouseNKeyHidDevice prior to SMR Oct-2022 Release 1 leaks MAC address of the connected Bluetooth device.
Published 2022-10-07 · Modified
5.9EPSS 0.001
CVE-2024-20060
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541754.
Published 2024-05-06 · Analyzed
5.9EPSS 0.001
CVE-2024-0027
In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-05-07 · Analyzed
5.9EPSS 0.001
CVE-2022-33729
Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.
Published 2022-08-05 · Modified
5.9EPSS 0.001
CVE-2022-36861
Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.
Published 2022-09-09 · Modified
5.9EPSS 0.001
CVE-2022-48443
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
5.9EPSS 0.001
CVE-2022-48444
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
5.9EPSS 0.001
CVE-2022-48445
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-06-06 · Modified
5.9EPSS 0.001
CVE-2022-39885
Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.
Published 2022-11-09 · Modified
5.9EPSS 0.001
CVE-2022-39886
Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.
Published 2022-11-09 · Modified
5.9EPSS 0.001
CVE-2022-39879
Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.
Published 2022-11-09 · Modified
5.9EPSS 0.001
CVE-2024-20840
Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using hardware keyboard to use VoiceRecorder on the lock screen.
Published 2024-03-05 · Analyzed
5.7EPSS 0.002
CVE-2022-39899
Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.
Published 2022-12-08 · Modified
5.7EPSS 0.001
CVE-2025-20643
In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS09291146; Issue ID: MSV-2056.
Published 2025-02-03 · Analyzed
5.7EPSS 0.001
CVE-2022-47363
In wlan driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
5.7EPSS 0.001
CVE-2022-47364
In wlan driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
5.7EPSS 0.001
CVE-2022-47368
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
5.7EPSS 0.001
CVE-2022-47369
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
Published 2023-02-06 · Modified
5.7EPSS 0.001
CVE-2023-52349
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Published 2024-04-08 · Modified
5.6EPSS 0.001
CVE-2022-20494
In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-243794204
Published 2023-01-24 · Modified
5.5EPSS 0.004
CVE-2024-0030
In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-02-16 · Analyzed
5.5EPSS 0.004
CVE-2022-39915
Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information via implicit intent.
Published 2022-12-08 · Modified
5.5EPSS 0.003
CVE-2023-52343
In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information disclosure no additional execution privileges needed
Published 2024-04-08 · Analyzed
5.5EPSS 0.003
CVE-2022-27821
Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via crafted image file.
Published 2022-04-11 · Modified
5.5EPSS 0.003
CVE-2022-20413
In start of Threads.cpp, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235850634
Published 2022-10-11 · Modified
5.5EPSS 0.003
CVE-2023-35671
In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-09-11 · Modified
5.5EPSS 0.002
CVE-2023-40121
In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-27 · Modified
5.5EPSS 0.002
CVE-2023-33898
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.002
CVE-2023-35683
In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-09-11 · Modified
5.5EPSS 0.002
CVE-2023-21285
In setMetadata of MediaSessionRecord.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-08-14 · Modified
5.5EPSS 0.002
CVE-2021-39670
In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-204087139
Published 2022-05-10 · Modified
5.5EPSS 0.002
CVE-2023-21288
In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
Published 2023-08-14 · Modified
5.5EPSS 0.002
CVE-2023-21284
In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
Published 2023-08-14 · Modified
5.5EPSS 0.002
CVE-2023-20909
In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-243130512
Published 2023-04-19 · Modified
5.5EPSS 0.002
CVE-2022-38689
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2022-10-14 · Modified
5.5EPSS 0.002
CVE-2023-40133
In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-27 · Modified
5.5EPSS 0.002
CVE-2023-21238
In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-07-12 · Modified
5.5EPSS 0.002
CVE-2022-20499
In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-246539931
Published 2023-03-24 · Modified
5.5EPSS 0.002
CVE-2022-20453
In update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error. This could lead to local denial of service of SIM recognition with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-240685104
Published 2022-11-08 · Modified
5.5EPSS 0.002
CVE-2023-33902
In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.002
← Prev28 / 48Next →