VulnSea

Android vulnerabilities

CVEs whose affected-version data names the Android package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

243 CVEsRSS

CVE-2026-45527Medium· 4.3
2w ago

In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow

In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed…

SunlitGoogle · AndroidEPSS 0.25%via NVD
CVE-2026-45525Low· 3.3
2w ago

In multiple locations, there is a possible improper data sanitization due to a logic error in the code

In multiple locations, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ex…

SunlitGoogle · AndroidEPSS 0.07%via NVD
CVE-2026-45521Low· 3.3
2w ago

In openFile of AppFuseBridge.java, there is a possible information disclosure due to a missing permission check

In openFile of AppFuseBridge.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need…

SunlitGoogle · AndroidEPSS 0.07%via NVD
CVE-2026-45520High· 7.8
2w ago

In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy

In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…

TwilightGoogle · AndroidEPSS 0.09%via NVD
CVE-2026-45519Low· 3.3
2w ago

In screenArgsForPermissionCheckIfAny of multiple locations there is a possible risk of unauthorized access due to a confused deputy

In screenArgsForPermissionCheckIfAny of multiple locations there is a possible risk of unauthorized access due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User int…

SunlitGoogle · AndroidEPSS 0.07%via NVD
CVE-2026-45515High· 7.8
2w ago

In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow

In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges nee…

TwilightGoogle · AndroidEPSS 0.10%via NVD
CVE-2026-28671Low· 3.3
2w ago

In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition

In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed…

SunlitGoogle · AndroidEPSS 0.06%via NVD
CVE-2026-28668High· 7.8
2w ago

In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code

In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

TwilightGoogle · AndroidEPSS 0.08%via NVD
CVE-2026-28666High· 8.8
2w ago

In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass

In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privilege…

TwilightGoogle · AndroidEPSS 0.29%via NVD
CVE-2026-28664High· 7.8
2w ago

In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code

In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

TwilightGoogle · AndroidEPSS 0.08%via NVD
CVE-2026-28662High· 8.0
2w ago

In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow

In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User …

Twilightgoogle · androidEPSS 0.12%via NVD
CVE-2026-58941High· 7.8
2w ago

In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation

In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee…

TwilightGoogle · AndroidEPSS 0.09%via NVD
CVE-2026-58874High· 7.8
2w ago

In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check

In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

TwilightGoogle · AndroidEPSS 0.07%via NVD
CVE-2026-58848High· 7.0
2w ago

In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition

In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

TwilightGoogle · AndroidEPSS 0.06%via NVD
CVE-2026-58846High· 7.8
2w ago

In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check

In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp…

TwilightGoogle · AndroidEPSS 0.08%via NVD
CVE-2026-58839High· 7.8
2w ago

In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow

In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp…

TwilightGoogle · AndroidEPSS 0.08%via NVD
CVE-2026-58822Critical· 9.8
2w ago

In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting

In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

MidnightGoogle · AndroidEPSS 0.31%via NVD
CVE-2026-55294High· 7.8
2w ago

In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow

In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

TwilightGoogle · AndroidEPSS 0.08%via NVD
CVE-2026-55273High· 7.8
2w ago

In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation

In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

TwilightGoogle · AndroidEPSS 0.08%via NVD
CVE-2026-28656High· 7.3
2w ago

In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack

In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is …

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0157Medium· 4.3
3mo ago

In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check

In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.17%via NVD
CVE-2026-0165Medium· 6.5
3mo ago

In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check

In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is n…

Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-0158Medium· 4.0
3mo ago

In Camera, there is a possible unauthorized way to access photos due to a missing permission check

In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi…

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-0155Medium· 5.3
3mo ago

In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check

In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploit…

Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-0145Medium· 4.0
3mo ago

In keymint, there is a possible Permission Bypass due to a logic error in the code

In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-0144High· 7.5
3mo ago

In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check

In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed fo…

Twilightgoogle · androidEPSS 0.27%via NVD
CVE-2026-0142Medium· 4.0
3mo ago

In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation

In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed …

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-0141Medium· 5.3
3mo ago

In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check

In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for expl…

Sunlitgoogle · androidEPSS 0.21%via NVD
CVE-2026-0140Medium· 4.3
3mo ago

In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow

In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-0134Medium· 4.0
3mo ago

In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code

In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User i…

Sunlitgoogle · androidEPSS 0.08%via NVD
Android vulnerabilities (CVEs) — page 7 · VulnSea