VendorsGoogleandroidall versions
Vulnerabilities

Google Android

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9603CVEs
CVE-2023-42696
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2025-48624
In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-12-08 · Modified
7.8EPSS 0.001
CVE-2025-48647
In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-01-16 · Analyzed
7.8EPSS 0.001
CVE-2024-49720
In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2025-09-02 · Analyzed
7.8EPSS 0.001
CVE-2023-21174
In isPageSearchEnabled of BillingCycleSettings.java, there is a possible way for the guest user to change data limits due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-235822222
Published 2023-06-28 · Modified
7.8EPSS 0.001
CVE-2022-20398
In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-221859734
Published 2022-09-13 · Modified
7.8EPSS 0.001
CVE-2026-0026
In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any system permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Published 2026-03-02 · Modified
7.8EPSS 0.001
CVE-2023-21172
In multiple functions of WifiCallingSettings.java, there is a possible way to change calling preferences for the admin user due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-262243015
Published 2023-06-28 · Modified
7.8EPSS 0.001
CVE-2026-56982
In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-15 · Analyzed
7.8EPSS 0.001
CVE-2023-21229
In registerServiceLocked of ManagedServices.java, there is a possible bypass of background activity launch restrictions due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-08-14 · Modified
7.8EPSS 0.001
CVE-2023-35666
In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-09-11 · Modified
7.8EPSS 0.001
CVE-2023-42694
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2022-20349
In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315522
Published 2022-08-09 · Modified
7.8EPSS 0.001
CVE-2023-42693
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42692
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42695
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2026-28580
In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-06-01 · Analyzed
7.8EPSS 0.001
CVE-2023-42739
In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42740
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2022-20274
In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of screen timeout with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-206470146
Published 2022-08-11 · Modified
7.8EPSS 0.001
CVE-2026-49918
In multiple functions, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
7.8EPSS 0.001
CVE-2023-42747
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-42743
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-21254
In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time permissions after the app is being killed due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-07-12 · Modified
7.8EPSS 0.001
CVE-2023-42736
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2026-55294
In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
7.8EPSS 0.001
CVE-2026-49927
In multiple locations, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
7.8EPSS 0.001
CVE-2026-58823
In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
7.8EPSS 0.001
CVE-2023-21081
In multiple functions of PackageInstallerService.java and related files, there is a possible way to bypass background activity launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-230492955
Published 2023-04-19 · Modified
7.8EPSS 0.001
CVE-2023-42738
In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2023-48402
In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2023-12-08 · Modified
7.8EPSS 0.001
CVE-2023-42748
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2026-58820
In multiple locations, there is a possible memory safety issue due to integer overflow. This could lead to local escalation of privilege with no additional execution privileges required.
Published 2026-09-08 · Analyzed
7.8EPSS 0.001
CVE-2023-21192
In setInputMethodWithSubtypeIdLocked of InputMethodManagerService.java, there is a possible way to setup input methods that are not enabled due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-227207653
Published 2023-06-28 · Modified
7.8EPSS 0.001
CVE-2026-45531
In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
7.8EPSS 0.001
CVE-2026-49884
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
7.8EPSS 0.001
CVE-2026-45515
In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
7.8EPSS 0.001
CVE-2024-43089
In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2024-11-13 · Analyzed
7.8EPSS 0.001
CVE-2023-42745
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
Published 2023-12-04 · Modified
7.8EPSS 0.001
CVE-2026-58839
In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-08 · Analyzed
7.8EPSS 0.001
← Prev99 / 241Next →