VendorsGoogleandroid13.0
Vulnerabilities

Google Android 13.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1587CVEs
CVE-2025-22431
In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due to a logic error in the code. This could lead to local denial of service until the phone reboots with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-02 · Analyzed
5.5EPSS 0.001
CVE-2024-34663
Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory.
Published 2024-10-08 · Analyzed
5.5EPSS 0.001
CVE-2022-20396
In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or user interaction, due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-234440688
Published 2022-09-13 · Modified
5.5EPSS 0.001
CVE-2024-49733
In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-01-21 · Analyzed
5.5EPSS 0.001
CVE-2023-42632
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42633
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42634
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42635
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42636
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42637
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42638
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42639
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42640
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42641
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42642
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42643
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42644
In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42646
In Ifaa service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42648
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42650
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42651
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-42652
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2025-26445
In offerNetwork of ConnectivityService.java, there is a possible leak of sensitive data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
5.5EPSS 0.001
CVE-2023-21234
In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-08-14 · Modified
5.5EPSS 0.001
CVE-2023-42654
In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2023-40633
In phasecheckserver, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-10-08 · Modified
5.5EPSS 0.001
CVE-2023-42631
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
Published 2023-11-01 · Modified
5.5EPSS 0.001
CVE-2025-20648
In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09456673; Issue ID: MSV-2584.
Published 2025-03-03 · Analyzed
5.5EPSS 0.001
CVE-2023-21260
In notification access permission dialog box, malicious application can embedded a very long service label that overflow the original user prompt and possibly contains mis-leading information to be appeared as a system message for user confirmation.
Published 2023-07-13 · Modified
5.5EPSS 0.001
CVE-2024-49736
In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-01-21 · Analyzed
5.5EPSS 0.001
CVE-2023-21290
In update of MmsProvider.java, there is a possible way to bypass file permission checks due to a race condition. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-08-14 · Modified
5.5EPSS 0.001
CVE-2022-44420
In modem, there is a possible missing verification of HashMME value in Security Mode Command. This could local denial of service with no additional execution privileges.
Published 2023-05-09 · Modified
5.5EPSS 0.001
CVE-2023-20942
In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-07-12 · Modified
5.5EPSS 0.001
CVE-2023-44216
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.
Published 2023-09-26 · Modified
5.3EPSS 0.018
CVE-2022-20530
In strings.xml, there is a possible permission bypass due to a misleading string. This could lead to remote information disclosure of call logs with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-231585645
Published 2022-12-16 · Modified
5.3EPSS 0.005
CVE-2023-52533
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
Published 2024-04-08 · Analyzed
5.3EPSS 0.004
CVE-2023-52344
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
Published 2024-04-08 · Analyzed
5.3EPSS 0.004
CVE-2023-40122
In applyCustomDescription of SaveUi.java, there is a possible way to view other user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-02-16 · Analyzed
5.3EPSS 0.003
CVE-2024-22006
OOB read in the TMU plugin that allows for memory disclosure in the power management subsystem of the device.
Published 2024-03-11 · Analyzed
5.3EPSS 0.002
CVE-2024-20147
In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389046 (Note: For MT79XX chipsets) / ALPS09136501 (Note: For MT2737, MT3603, MT6XXX, and MT8XXX chipsets); Issue ID: MSV-1797.
Published 2025-02-03 · Analyzed
5.3EPSS 0.002
← Prev32 / 40Next →