VendorsGoogleandroidany version
Vulnerabilities

Google Android any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3688CVEs
CVE-2026-13283
Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-25 · Analyzed
7.5EPSS 0.003
CVE-2017-13271
A elevation of privilege vulnerability in the upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-69006799.
Published 2018-04-04 · Modified
7.5EPSS 0.003
CVE-2017-14890
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in the processing of an SWBA event, the vdev_map value is not properly validated leading to a potential buffer overwrite in function wma_send_bcn_buf_ll().
Published 2018-04-03 · Modified
7.5EPSS 0.003
CVE-2017-14894
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in wma_vdev_start_resp_handler(), vdev id is received from firmware as part of WMI_VDEV_START_RESP_EVENTID. This vdev id can be greater than max bssid stored in wma handle and this would result in buffer overwrite while accessing wma_handle->interfaces[vdev_id].
Published 2018-04-03 · Modified
7.5EPSS 0.003
CVE-2018-5821
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in function wma_wow_wakeup_host_event(), wake_info->vdev_id is received from FW and is used directly as array index to access wma->interfaces whose max index should be (max_bssid-1). If wake_info->vdev_id is greater than or equal to max_bssid, an out-of-bounds read occurs.
Published 2018-04-03 · Modified
7.5EPSS 0.003
CVE-2017-15836
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, if the firmware sends a service ready event to the host with a large number in the num_hw_modes or num_phy, then it could result in an integer overflow which may potentially lead to a buffer overflow.
Published 2018-04-03 · Modified
7.5EPSS 0.003
CVE-2023-48398
In ProtocolNetAcBarringInfo::ProtocolNetAcBarringInfo() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
Published 2023-12-08 · Modified
7.5EPSS 0.003
CVE-2022-20370
Product: AndroidVersions: Android kernelAndroid ID: A-215730643References: N/A
Published 2022-08-11 · Modified
7.5EPSS 0.003
CVE-2022-20407
Product: AndroidVersions: Android kernelAndroid ID: A-210916981References: N/A
Published 2022-08-11 · Modified
7.5EPSS 0.003
CVE-2017-8279
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, missing race condition protection while updating msg mask table can lead to buffer over-read. Also access to freed memory can happen while updating msg_mask information.
Published 2017-11-16 · Modified
7.5EPSS 0.003
CVE-2026-57008
In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-15 · Analyzed
7.5EPSS 0.003
CVE-2017-13270
A elevation of privilege vulnerability in the upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-69474744.
Published 2018-04-04 · Modified
7.5EPSS 0.003
CVE-2023-21220
there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-264590585References: N/A
Published 2023-06-28 · Modified
7.5EPSS 0.003
CVE-2023-21219
there is a possible use of unencrypted transport over cellular networks due to an insecure default value. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-264698379References: N/A
Published 2023-06-28 · Modified
7.5EPSS 0.003
CVE-2022-20406
Product: AndroidVersions: Android kernelAndroid ID: A-184676385References: N/A
Published 2022-08-11 · Modified
7.5EPSS 0.003
CVE-2022-20408
Product: AndroidVersions: Android kernelAndroid ID: A-204782372References: N/A
Published 2022-08-11 · Modified
7.5EPSS 0.003
CVE-2021-0946
The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer via PMR_PDumpSymbolicAddr, and then copies the buffer to userspace. The method PMR_PDumpSymbolicAddr may fail, and if it does the buffer will be left uninitialized and despite the error will still be copied to userspace. Kernel leak of uninitialized heap data with no privs required.Product: AndroidVersions: Android SoCAndroid ID: A-236846966
Published 2022-08-24 · Modified
7.5EPSS 0.003
CVE-2021-0947
The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM, and then copies the buffer to userspace. The method TLServerDiscoverStreamsKM may fail for several reasons including invalid sizes. If this method fails the buffer will be left uninitialized and despite the error will still be copied to userspace. Kernel leak of uninitialized heap data with no privs required.Product: AndroidVersions: Android SoCAndroid ID: A-236838960
Published 2022-08-24 · Modified
7.5EPSS 0.003
CVE-2022-20380
Product: AndroidVersions: Android kernelAndroid ID: A-212625740References: N/A
Published 2022-08-11 · Modified
7.5EPSS 0.003
CVE-2022-20404
Product: AndroidVersions: Android kernelAndroid ID: A-205714161References: N/A
Published 2022-08-11 · Modified
7.5EPSS 0.003
CVE-2024-32924
In DeregAcceptProcINT of cn_NrmmStateDeregInit.cpp, there is a possible denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-06-13 · Analyzed
7.5EPSS 0.003
CVE-2021-0891
An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Product: AndroidVersions: Android SoCAndroid ID: A-236849490
Published 2022-08-24 · Modified
7.5EPSS 0.003
CVE-2026-13856
Insufficient validation of untrusted input in Speech in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-30 · Analyzed
7.5EPSS 0.003
CVE-2023-21227
In HTBLogKM of htbserver.c, there is a possible information disclosure due to log information disclosure. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-04 · Modified
7.5EPSS 0.003
CVE-2023-35652
In ProtocolEmergencyCallListIndAdapter::Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for exploitation.
Published 2023-10-11 · Modified
7.5EPSS 0.003
CVE-2026-17816
Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-07-30 · Analyzed
7.5EPSS 0.003
CVE-2023-21061
Product: AndroidVersions: Android kernelAndroid ID: A-229255400References: N/A
Published 2023-03-24 · Modified
7.5EPSS 0.003
CVE-2026-0109
In dhd_tcpdata_info_get of dhd_ip.c, there is a possible Denial of Service due to a precondition check failure. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-03-10 · Analyzed
7.5EPSS 0.003
CVE-2024-53834
In sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-01-03 · Analyzed
7.5EPSS 0.003
CVE-2022-20560
Product: AndroidVersions: Android kernelAndroid ID: A-212623833References: N/A
Published 2022-12-16 · Modified
7.5EPSS 0.003
CVE-2026-17698
Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published 2026-07-30 · Analyzed
7.5EPSS 0.003
CVE-2026-0144
In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2026-0136
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-06-16 · Modified
7.5EPSS 0.003
CVE-2023-21067
Product: AndroidVersions: Android kernelAndroid ID: A-254114726References: N/A
Published 2023-03-24 · Modified
7.5EPSS 0.003
CVE-2025-36894
In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-04 · Analyzed
7.5EPSS 0.003
CVE-2022-42539
Information disclosure
Published 2023-11-29 · Modified
7.5EPSS 0.003
CVE-2023-35656
In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-18 · Modified
7.5EPSS 0.003
CVE-2023-35663
In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-10-18 · Modified
7.5EPSS 0.003
CVE-2024-44100
Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.
Published 2024-10-25 · Analyzed
7.5EPSS 0.003
CVE-2024-32902
Remote prevention of access to cellular service with no user interaction (for example, crashing the cellular radio service with a malformed packet)
Published 2024-06-13 · Modified
7.5EPSS 0.002
← Prev59 / 93Next →