VendorsGoogleandroidany version
Vulnerabilities

Google Android any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3688CVEs
CVE-2017-5066
Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to incorrectly accept a badly formed X.509 certificate via a crafted HTML page.
Published 2017-10-27 · Modified
6.5EPSS 0.007
CVE-2023-38131
Improper input validationation for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access.
Published 2023-11-14 · Modified
6.5EPSS 0.007
CVE-2023-22290
Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access.
Published 2023-11-14 · Modified
6.5EPSS 0.007
CVE-2022-0455
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Published 2022-04-05 · Modified
6.5EPSS 0.007
CVE-2022-40961
During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 105.
Published 2022-12-22 · Modified
6.5EPSS 0.006
CVE-2022-4926
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-07-28 · Modified
6.5EPSS 0.006
CVE-2023-0130
Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-01-10 · Modified
6.5EPSS 0.006
CVE-2023-0133
Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main origin permission delegation via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-01-10 · Modified
6.5EPSS 0.006
CVE-2022-3310
Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chromium security severity: Medium)
Published 2022-11-01 · Modified
6.5EPSS 0.006
CVE-2023-0697
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: High)
Published 2023-02-07 · Modified
6.5EPSS 0.005
CVE-2015-3830
The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows remote attackers to trick a victim by displaying a malicious page for legitimate domain names.
Published 2017-06-06 · Modified
6.5EPSS 0.005
CVE-2022-26527
Realtek Linux/Android Bluetooth Mesh SDK - Buffer Overflow
Published 2022-08-30 · Modified
6.5EPSS 0.005
CVE-2022-26528
Realtek Linux/Android Bluetooth Mesh SDK - Buffer Overflow
Published 2022-08-30 · Modified
6.5EPSS 0.005
CVE-2022-26529
Realtek Linux/Android Bluetooth Mesh SDK - Buffer Overflow
Published 2022-08-30 · Modified
6.5EPSS 0.005
CVE-2022-36317
When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.
Published 2022-12-22 · Modified
6.5EPSS 0.005
CVE-2025-0246
Address bar spoofing using an invalid protocol scheme on Firefox for Android
Published 2025-01-07 · Modified
6.5EPSS 0.004
CVE-2017-9681
In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if kernel memory address is passed from userspace through iris_vidioc_s_ext_ctrls ioctl, it will print kernel address data. A user could set it to an arbitrary kernel address, hence information disclosure (for kernel) could occur.
Published 2018-03-30 · Modified
6.5EPSS 0.004
CVE-2022-25635
Realtek Linux/Android Bluetooth Mesh SDK - Buffer Overflow
Published 2022-08-30 · Modified
6.5EPSS 0.004
CVE-2026-13924
Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
CVE-2026-78977
Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published 2026-08-25 · Analyzed
6.5EPSS 0.003
CVE-2026-17968
Uninitialized Use in WebXR in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Published 2026-07-30 · Analyzed
6.5EPSS 0.003
CVE-2026-13943
Uninitialized Use in CSS in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
CVE-2026-13923
Uninitialized Use in GPU in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
CVE-2026-9917
Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
6.5EPSS 0.003
CVE-2026-76039
Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
Published 2026-08-18 · Analyzed
6.5EPSS 0.003
CVE-2026-14088
Uninitialized Use in Canvas in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
CVE-2026-14008
Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
CVE-2026-9912
Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
6.5EPSS 0.003
CVE-2026-79288
Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
Published 2026-08-25 · Analyzed
6.5EPSS 0.003
CVE-2026-87565
Information leak in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published 2026-09-09 · Analyzed
6.5EPSS 0.003
CVE-2026-79239
Out of bounds read in Tint in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published 2026-08-25 · Analyzed
6.5EPSS 0.003
CVE-2026-13816
Insufficient validation of untrusted input in File Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
CVE-2026-79241
Out of bounds read in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-08-25 · Analyzed
6.5EPSS 0.003
CVE-2026-13910
Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
CVE-2026-79124
Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published 2026-08-25 · Analyzed
6.5EPSS 0.003
CVE-2022-20217
There is a unauthorized broadcast in the SprdContactsProvider. A third-party app could use this issue to delete Fdn contact.Product: AndroidVersions: Android SoCAndroid ID: A-232441378
Published 2022-07-13 · Modified
6.5EPSS 0.003
CVE-2026-11007
Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
6.5EPSS 0.003
CVE-2026-13936
Inappropriate implementation in Passwords in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
CVE-2026-13949
Insufficient policy enforcement in Payments in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
CVE-2026-13954
Insufficient policy enforcement in XML in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-30 · Analyzed
6.5EPSS 0.003
← Prev70 / 93Next →