VendorsGoogleandroid13.0
Vulnerabilities

Google Android 13.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1587CVEs
CVE-2023-52346
In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed
Published 2024-04-08 · Analyzed
4.4EPSS 0.001
CVE-2023-32819
In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07993705; Issue ID: ALPS08014138.
Published 2023-10-02 · Modified
4.4EPSS 0.001
CVE-2023-48342
In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Published 2024-01-18 · Modified
4.4EPSS 0.001
CVE-2023-48353
In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed
Published 2024-01-18 · Modified
4.4EPSS 0.001
CVE-2023-52348
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Published 2024-04-08 · Analyzed
4.4EPSS 0.001
CVE-2024-23658
In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed
Published 2024-04-08 · Analyzed
4.4EPSS 0.001
CVE-2023-40651
In urild service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Published 2023-10-08 · Modified
4.4EPSS 0.001
CVE-2024-20036
In vdec, there is a possible permission bypass due to a permissions bypass. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08509508; Issue ID: ALPS08509508.
Published 2024-03-04 · Analyzed
4.4EPSS 0.001
CVE-2022-48456
In camera driver, there is a possible out of bounds write due to a incorrect bounds check. This could lead to local denial of service with System execution privileges needed
Published 2023-11-01 · Modified
4.4EPSS 0.001
CVE-2022-48461
In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Published 2023-11-01 · Modified
4.4EPSS 0.001
CVE-2023-48339
In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
Published 2024-01-18 · Modified
4.4EPSS 0.001
CVE-2023-48355
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Published 2024-01-18 · Modified
4.4EPSS 0.001
CVE-2023-48356
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Published 2024-01-18 · Modified
4.4EPSS 0.001
CVE-2023-48357
In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Published 2024-01-18 · Modified
4.4EPSS 0.001
CVE-2023-48358
In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Published 2024-01-18 · Modified
4.4EPSS 0.001
CVE-2023-48359
In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed
Published 2024-01-18 · Modified
4.4EPSS 0.001
CVE-2023-52536
In faceid service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Published 2024-04-08 · Modified
4.4EPSS 0.001
CVE-2023-52535
In vsp driver, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed
Published 2024-04-08 · Analyzed
4.4EPSS 0.001
CVE-2024-20112
In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730.
Published 2024-11-04 · Analyzed
4.4EPSS 0.001
CVE-2024-49421
Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location.
Published 2024-12-03 · Analyzed
4.3EPSS 0.003
CVE-2022-20541
In phNxpNciHal_ioctl of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-238083126
Published 2022-12-16 · Modified
4.2EPSS 0.002
CVE-2023-21462
The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.
Published 2023-03-16 · Modified
4.2EPSS 0.002
CVE-2024-20026
In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541632.
Published 2024-03-04 · Analyzed
4.2EPSS 0.001
CVE-2025-20744
In pda, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10127160; Issue ID: MSV-4542.
Published 2025-11-04 · Analyzed
4.2EPSS 0.001
CVE-2025-20745
In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10095441; Issue ID: MSV-4294.
Published 2025-11-04 · Analyzed
4.2EPSS 0.001
CVE-2024-34664
Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypass Knox Guard in a multi-user environment.
Published 2024-10-08 · Analyzed
4.1EPSS 0.001
CVE-2022-32645
In vow, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494477; Issue ID: ALPS07494477.
Published 2023-01-03 · Modified
4.1EPSS 0.001
CVE-2025-20651
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291294; Issue ID: MSV-2062.
Published 2025-03-03 · Analyzed
4.1EPSS 0.001
CVE-2023-20717
In vcu, there is a possible leak of dma buffer due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645185; Issue ID: ALPS07645185.
Published 2023-05-15 · Modified
4.1EPSS 0.001
CVE-2023-20620
In adsp, there is a possible escalation of privilege due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07554558; Issue ID: ALPS07554558.
Published 2023-03-07 · Modified
4.1EPSS 0.001
CVE-2023-20750
In swpm, there is a possible out of bounds write due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780926; Issue ID: ALPS07780928.
Published 2023-06-06 · Modified
4.1EPSS 0.001
CVE-2022-48451
In bluetooth service, there is a possible out of bounds write due to race condition. This could lead to local denial of service with System execution privileges needed.
Published 2023-07-12 · Modified
4.1EPSS 0.001
CVE-2023-21178
In installKey of KeyUtil.cpp, there is a possible failure of file encryption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-140762419
Published 2023-06-28 · Modified
4.1EPSS 0.001
CVE-2025-26417
In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-08-26 · Analyzed
4.0EPSS 0.003
CVE-2023-21463
Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific conditions.
Published 2023-03-16 · Modified
4.0EPSS 0.001
CVE-2023-21464
Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper status.
Published 2023-03-16 · Modified
4.0EPSS 0.001
CVE-2022-39898
Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.
Published 2022-12-08 · Modified
4.0EPSS 0.001
CVE-2022-39903
Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.
Published 2022-12-08 · Modified
4.0EPSS 0.001
CVE-2025-26421
In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
4.0EPSS 0.001
CVE-2024-20065
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08698617; Issue ID: MSV-1394.
Published 2024-06-03 · Analyzed
4.0EPSS 0.001
← Prev38 / 40Next →