VendorsGoogleandroid13.0
Vulnerabilities

Google Android 13.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1587CVEs
CVE-2023-21240
In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-21280
In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-08-14 · Modified
5.5EPSS 0.001
CVE-2025-0082
In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Published 2025-08-26 · Analyzed
5.5EPSS 0.001
CVE-2022-47487
In thermal service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service local denial of service with no additional execution privileges.
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2025-48559
In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
5.5EPSS 0.001
CVE-2023-21087
In PreferencesHelper.java, an uncaught exception may cause the device to get stuck in a boot loop. This could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-261723753
Published 2023-04-19 · Modified
5.5EPSS 0.001
CVE-2023-21239
In visitUris of Notification.java, there is a possible way to leak image data across user boundaries due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-20703
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767853; Issue ID: ALPS07767853.
Published 2023-05-15 · Modified
5.5EPSS 0.001
CVE-2023-20704
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767826; Issue ID: ALPS07767826.
Published 2023-05-15 · Modified
5.5EPSS 0.001
CVE-2023-20705
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767870; Issue ID: ALPS07767870.
Published 2023-05-15 · Modified
5.5EPSS 0.001
CVE-2023-20706
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767860; Issue ID: ALPS07767860.
Published 2023-05-15 · Modified
5.5EPSS 0.001
CVE-2025-26453
In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
5.5EPSS 0.001
CVE-2022-44419
In modem, there is a possible missing verification of NAS Security Mode Command Replay Attacks in LTE. This could local denial of service with no additional execution privileges.
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2022-48370
In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2022-48371
In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2023-21016
In AccountTypePreference of AccountTypePreference.java, there is a possible way to mislead the user about accounts installed on the device due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-213905884
Published 2023-03-24 · Modified
5.5EPSS 0.001
CVE-2023-21026
In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable region beyond its own SurfaceControl due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-254681548
Published 2023-03-24 · Modified
5.5EPSS 0.001
CVE-2023-21033
In addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-244713323
Published 2023-03-24 · Modified
5.5EPSS 0.001
CVE-2023-40085
In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-02-16 · Analyzed
5.5EPSS 0.001
CVE-2023-40123
In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-27 · Modified
5.5EPSS 0.001
CVE-2023-40124
In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-02-15 · Analyzed
5.5EPSS 0.001
CVE-2023-40139
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-27 · Modified
5.5EPSS 0.001
CVE-2022-48232
In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2022-48233
In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2022-48234
In FM service , there is a possible missing params check. This could lead to local denial of service in FM service .
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2023-21249
In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-35664
In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-09-11 · Modified
5.5EPSS 0.001
CVE-2023-20935
In deserialize of multiple files, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-256589724
Published 2023-04-19 · Modified
5.5EPSS 0.001
CVE-2022-47490
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2022-47492
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2022-47493
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2025-48603
In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-12-08 · Modified
5.5EPSS 0.001
CVE-2025-48576
In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-12-08 · Analyzed
5.5EPSS 0.001
CVE-2022-48376
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2022-48377
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2022-48379
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2023-21080
In register_notification_rsp of btif_rc.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-245916076
Published 2023-04-19 · Modified
5.5EPSS 0.001
CVE-2023-21112
In AnalyzeMfcResp of NxpMfcReader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-252763983
Published 2023-05-15 · Modified
5.5EPSS 0.001
CVE-2023-21177
In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-273906410
Published 2023-06-28 · Modified
5.5EPSS 0.001
CVE-2023-21230
In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi access point change and its BSSID or SSID due to a precondition check failure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-08-14 · Modified
5.5EPSS 0.001
← Prev29 / 40Next →