VendorsGoogleandroidany version
Vulnerabilities

Google Android any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3688CVEs
CVE-2026-48354
CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)
Published 2026-07-14 · Analyzed
6.2EPSS 0.003
CVE-2025-65835
The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses Intent.EXTRA_CHOSEN_COMPONENT without checking for null. If a broadcast is sent with extras present but without EXTRA_CHOSEN_COMPONENT, the code dereferences a null value and throws a NullPointerException. Because the receiver is exported and performs no permission or caller validation, any local application on the device can send crafted ACTION_SEND broadcasts to this component and repeatedly crash the host application, resulting in a local, unauthenticated application-level denial of service for any app that includes the plugin.
Published 2025-12-15 · Analyzed
6.2EPSS 0.003
CVE-2026-48302
CAI Content Credentials | Improper Input Validation (CWE-20)
Published 2026-07-14 · Analyzed
6.2EPSS 0.003
CVE-2026-48296
CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2026-07-14 · Analyzed
6.2EPSS 0.003
CVE-2026-48298
CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)
Published 2026-07-14 · Analyzed
6.2EPSS 0.003
CVE-2026-48357
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)
Published 2026-07-14 · Analyzed
6.2EPSS 0.003
CVE-2026-0248
Prisma Access Agent: Improper Certificate Validation Vulnerability
Published 2026-05-13 · Analyzed
6.2EPSS 0.002
CVE-2022-39912
Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.
Published 2022-12-08 · Modified
6.2EPSS 0.001
CVE-2026-56888
In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-15 · Analyzed
6.2EPSS 0.001
CVE-2026-58731
In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-15 · Analyzed
6.2EPSS 0.001
CVE-2026-56892
In ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-15 · Analyzed
6.2EPSS 0.001
CVE-2024-29754
In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-04-05 · Analyzed
6.2EPSS 0.001
CVE-2024-27218
In update_freq_data of , there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-03-11 · Modified
6.2EPSS 0.001
CVE-2024-8897
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as the trusted site. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 130.0.1.
Published 2024-09-17 · Modified
6.1EPSS 0.076
CVE-2012-0767
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.
Published 2012-02-16 · Analyzed
6.1KEVEPSS 0.064
CVE-2021-38000
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
Published 2021-11-23 · Analyzed
6.1KEVEPSS 0.049
CVE-2021-43530
A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.
Published 2021-12-08 · Modified
6.1EPSS 0.014
CVE-2017-5045
XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe load, which allowed a remote attacker to brute force JavaScript variables via a crafted HTML page.
Published 2017-04-24 · Modified
6.1EPSS 0.012
CVE-2021-38641
Microsoft Edge for Android Spoofing Vulnerability
Published 2021-09-02 · Modified
6.1EPSS 0.012
CVE-2017-5069
Incorrect MIME type of XSS-Protection reports in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to circumvent Cross-Origin Resource Sharing checks via a crafted HTML page.
Published 2017-10-27 · Modified
6.1EPSS 0.012
CVE-2014-4925
Cross-site scripting (XSS) vulnerability in Good for Enterprise for Android 2.8.0.398 and 1.9.0.40.
Published 2017-08-28 · Modified
6.1EPSS 0.011
CVE-2021-34425
Server Side Request Forgery in Zoom Client for Meetings chat
Published 2021-12-14 · Modified
6.1EPSS 0.008
CVE-2020-36486
Swift File Transfer Mobile v1.1.2 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the 'path' parameter of the 'list' and 'download' exception-handling.
Published 2021-10-22 · Modified
6.1EPSS 0.007
CVE-2021-43544
When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.
Published 2021-12-08 · Modified
6.1EPSS 0.005
CVE-2022-45413
Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 107.
Published 2022-12-22 · Modified
6.1EPSS 0.004
CVE-2024-38208
Microsoft Edge for Android Spoofing Vulnerability
Published 2024-08-22 · Modified
6.1EPSS 0.004
CVE-2022-29910
When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 100.
Published 2022-12-22 · Modified
6.1EPSS 0.004
CVE-2026-87640
Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-09-09 · Modified
6.1EPSS 0.003
CVE-2024-8907
Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (XSS) via a crafted set of UI gestures. (Chromium security severity: Medium)
Published 2024-09-17 · Analyzed
6.1EPSS 0.003
CVE-2015-8956
The rfcomm_sock_bind function in net/bluetooth/rfcomm/sock.c in the Linux kernel before 4.2 allows local users to obtain sensitive information or cause a denial of service (NULL pointer dereference) via vectors involving a bind system call on a Bluetooth RFCOMM socket.
Published 2016-10-10 · Modified
6.1EPSS 0.002
CVE-2026-11034
Insufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
6.1EPSS 0.002
CVE-2024-32918
Permission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization steps
Published 2024-06-13 · Modified
6.1EPSS 0.001
CVE-2026-17872
Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-07-30 · Analyzed
6.1EPSS 0.001
CVE-2021-26439
Microsoft Edge for Android Information Disclosure Vulnerability
Published 2021-09-02 · Modified
5.9EPSS 0.029
CVE-2022-23278
Microsoft Defender for Endpoint Spoofing Vulnerability
Published 2022-03-09 · Modified
5.9EPSS 0.019
CVE-2017-7770
A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This would allow a malicious site to displayed a spoofed addressbar, showing the location of an arbitrary website instead of the one loaded. Note: this issue only affects Firefox for Android. Desktop Firefox is unaffected. This vulnerability affects Firefox < 54.
Published 2018-06-11 · Modified
5.9EPSS 0.011
CVE-2015-0874
Smartphone Passbook 1.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information from encrypted communications via a crafted certificate.
Published 2017-09-26 · Modified
5.9EPSS 0.008
CVE-2018-0691
Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Published 2018-11-15 · Modified
5.9EPSS 0.007
CVE-2017-2278
The RBB SPEED TEST App for Android version 2.0.3 and earlier, RBB SPEED TEST App for iOS version 2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Published 2017-08-02 · Modified
5.9EPSS 0.006
CVE-2016-6709
An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-the-middle attacker to gain access to sensitive information if a non-standard cipher suite is used by an application. This issue is rated as High because it could be used to access data without permission. Android ID: A-31081987.
Published 2016-11-25 · Modified
5.9EPSS 0.005
← Prev73 / 93Next →