VendorsGoogleandroid13.0
Vulnerabilities

Google Android 13.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1587CVEs
CVE-2023-33910
In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
Published 2023-08-07 · Modified
5.5EPSS 0.001
CVE-2023-33912
In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
Published 2023-08-07 · Modified
5.5EPSS 0.001
CVE-2022-47335
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
Published 2023-04-11 · Modified
5.5EPSS 0.001
CVE-2022-47336
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
Published 2023-04-11 · Modified
5.5EPSS 0.001
CVE-2022-47337
In media service, there is a missing permission check. This could lead to local denial of service in media service.
Published 2023-04-11 · Modified
5.5EPSS 0.001
CVE-2022-47362
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
Published 2023-04-11 · Modified
5.5EPSS 0.001
CVE-2022-47463
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
Published 2023-04-11 · Modified
5.5EPSS 0.001
CVE-2022-47464
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
Published 2023-04-11 · Modified
5.5EPSS 0.001
CVE-2022-47465
In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.
Published 2023-04-11 · Modified
5.5EPSS 0.001
CVE-2025-26448
In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
5.5EPSS 0.001
CVE-2025-48604
In multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-12-08 · Modified
5.5EPSS 0.001
CVE-2024-27235
In plugin_extern_func of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-03-11 · Analyzed
5.5EPSS 0.001
CVE-2023-42647
In Ifaa service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42649
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2025-48524
In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
5.5EPSS 0.001
CVE-2023-21091
In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-257954050
Published 2023-04-19 · Modified
5.5EPSS 0.001
CVE-2023-21141
In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-262244249
Published 2023-06-15 · Modified
5.5EPSS 0.001
CVE-2023-21142
In multiple files, there is a possible way to access traces in the dev mode due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-262243665
Published 2023-06-15 · Modified
5.5EPSS 0.001
CVE-2023-30936
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2025-26442
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
5.5EPSS 0.001
CVE-2023-40108
In multiple locations, there is a possible way to access media content belonging to another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-01-21 · Modified
5.5EPSS 0.001
CVE-2023-20824
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID: ALPS07951402.
Published 2023-09-04 · Modified
5.5EPSS 0.001
CVE-2023-20825
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID: ALPS07951413.
Published 2023-09-04 · Modified
5.5EPSS 0.001
CVE-2023-20826
In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07978550; Issue ID: ALPS07978550.
Published 2023-09-04 · Modified
5.5EPSS 0.001
CVE-2023-48354
In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed
Published 2024-01-18 · Modified
5.5EPSS 0.001
CVE-2023-52347
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Published 2024-04-08 · Analyzed
5.5EPSS 0.001
CVE-2025-48601
In multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-12-08 · Analyzed
5.5EPSS 0.001
CVE-2023-21082
In getNumberFromCallIntent of NewOutgoingCallIntentBroadcaster.java, there is a possible way to enumerate other user's contact phone number due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-257030107
Published 2023-04-19 · Modified
5.5EPSS 0.001
CVE-2023-21104
In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-259938771
Published 2023-05-15 · Modified
5.5EPSS 0.001
CVE-2024-40656
In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Published 2024-09-11 · Analyzed
5.5EPSS 0.001
CVE-2023-32825
In bluethooth service, there is a possible out of bounds reads due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07884130; Issue ID: ALPS07884130.
Published 2023-11-06 · Modified
5.5EPSS 0.001
CVE-2023-40105
In backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-02-15 · Analyzed
5.5EPSS 0.001
CVE-2023-40113
In multiple locations, there is a possible way for apps to access cross-user message data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-02-15 · Analyzed
5.5EPSS 0.001
CVE-2025-26449
In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
5.5EPSS 0.001
CVE-2025-22431
In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logic error in the code. This could lead to local denial of service until the phone reboots with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-02 · Analyzed
5.5EPSS 0.001
CVE-2023-48352
In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
Published 2024-01-18 · Modified
5.5EPSS 0.001
CVE-2023-52350
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Published 2024-04-08 · Modified
5.5EPSS 0.001
CVE-2025-26429
In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
5.5EPSS 0.001
CVE-2025-48542
In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
5.5EPSS 0.001
CVE-2024-34663
Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory.
Published 2024-10-08 · Analyzed
5.5EPSS 0.001
← Prev31 / 40Next →