VulnSea

Android vulnerabilities

CVEs whose affected-version data names the Android package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

243 CVEsRSS

CVE-2026-0130Medium· 4.3
3mo ago

In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow

In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploita…

Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-0136High· 7.5
3mo ago

In Modem, there is a possible out of bounds read due to a missing bounds check

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.27%via NVD
CVE-2026-0129Medium· 4.3
3mo ago

In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check

In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

Sunlitgoogle · androidEPSS 0.18%via NVD
CVE-2026-0156High· 7.5
3mo ago

In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check

In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed…

Twilightgoogle · androidEPSS 0.22%via NVD
CVE-2026-0128Medium· 6.5⚖ disputed
3mo ago

In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow

In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for explo…

Sunlitgoogle · androidEPSS 0.19%via NVD
CVE-2026-28581Medium· 4.0
3mo ago

In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code

In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local escalation with User execution privileges needed. User interaction …

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-0009High· 7.8PoC
3mo ago

In multiple locations, there is a possible tapjacking due to a logic error in the code

In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Midnightgoogle · androidEPSS 0.09%via NVD
CVE-2026-0100High· 7.8
3mo ago

In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow

In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0099High· 7.8
3mo ago

In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code

In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges n…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0098High· 7.8
3mo ago

In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy

In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User intera…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0097High· 8.0
3mo ago

In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error

In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges neede…

Twilightgoogle · androidEPSS 0.12%via NVD
CVE-2026-0096High· 7.8
3mo ago

In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI

In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0095High· 8.0
3mo ago

In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow

In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional exe…

Twilightgoogle · androidEPSS 0.11%via NVD
CVE-2026-0094High· 7.8
3mo ago

In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI

In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional ex…

Twilightgoogle · androidEPSS 0.06%via NVD
CVE-2026-0093High· 7.8
3mo ago

In multiple locations, there is a possible misleading UI due to obfuscation

In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0091High· 7.8PoC
3mo ago

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

Midnightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0089High· 7.8
3mo ago

In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check

In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed.…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0088High· 7.8
3mo ago

In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI

In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges nee…

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-0087High· 7.8
3mo ago

In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code

In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could lead to local escalation of privilege with no additional execution …

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-0086Medium· 6.8
3mo ago

In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check

In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti…

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-0085Medium· 5.5
3mo ago

In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation

In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User i…

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-0080Medium· 6.5
3mo ago

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not…

Sunlitgoogle · androidEPSS 0.27%via NVD
CVE-2026-0078High· 7.8
3mo ago

In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation

In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-0077High· 7.8
3mo ago

In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code

In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges nee…

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2025-48651Medium· 5.5
5mo ago

In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation

In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed…

Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-0008High· 8.4
6mo ago

In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy

In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo…

Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-0012Medium· 6.2
6mo ago

In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code

In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User inter…

Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-0013High· 8.4PoC
6mo ago

In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy

In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…

Midnightgoogle · androidEPSS 0.16%via NVD
CVE-2026-0011High· 8.4
6mo ago

In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code

In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed…

Twilightgoogle · androidEPSS 0.13%via NVD
CVE-2026-0010High· 8.4PoC
6mo ago

In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check

In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…

Midnightgoogle · androidEPSS 0.12%via NVD
Android vulnerabilities (CVEs) — page 8 · VulnSea