google / android
411 known vulnerabilities in google android.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-9892 | Medium | 0.2% | 8.3 | Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.… | |
| CVE-2026-10020 | Medium | 0.2% | 8.3 | Insufficient validation of untrusted input in Skia in Google Chrome on Android p… | |
| CVE-2026-9123 | Medium | 0.2% | 7.5 | Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS … | |
| CVE-2026-10014 | Medium | 0.2% | 8.3 | Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 al… | |
| CVE-2026-9977 | Medium | 0.2% | 8.3 | Insufficient validation of untrusted input in WebShare in Google Chrome on Andro… | |
| CVE-2026-41154 | Medium | 0.2% | 7.8 | Software installed and run as a non-privileged user may cause OOB kernel memory … | |
| CVE-2026-7639 | Medium | 0.2% | 7.8 | Software installed and run as a non-privileged user may conduct a sequence of im… | |
| CVE-2026-19143 | Medium | 0.2% | 8.6 | Insufficient validation of untrusted input in WebAPKs in Google Chrome on Androi… | |
| CVE-2026-34196 | Medium | 0.2% | 7.8 | Software installed and run as a non-privileged user may conduct improper GPU sys… | |
| CVE-2026-0013 | Medium | 0.2% | 8.4 | In setupLayout of PickActivity.java, there is a possible way to start any activi… | |
| CVE-2026-45196 | Medium | 0.1% | 7.8 | Kernel software installed and running inside a Host VM may post improper command… | |
| CVE-2026-0011 | Medium | 0.1% | 8.4 | In enableSystemPackageLPw of Settings.java, there is a possible way to prevent l… | |
| CVE-2026-45203 | Medium | 0.1% | 7.8 | Kernel software installed and running inside a Host VM may post improper command… | |
| CVE-2026-28662 | Medium | 0.1% | 8.0 | In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of b… | |
| CVE-2026-0097 | Medium | 0.1% | 8.0 | In multiple locations, there is a possible way to bypass user interaction when p… | |
| CVE-2026-0010 | Medium | 0.1% | 8.4 | In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write… | |
| CVE-2026-0059 | Medium | 0.1% | 8.0 | In multiple functions of sdp_discovery.cc, there is a possible way to achieve co… | |
| CVE-2026-49743 | Medium | 0.1% | 7.8 | Software installed and run as a non-privileged user may conduct improper GPU sys… | |
| CVE-2026-49744 | Medium | 0.1% | 7.8 | Kernel software installed and running inside a Guest VM may post improper comman… | |
| CVE-2026-49745 | Medium | 0.1% | 7.8 | Kernel software installed and running inside a Guest VM may post improper comman… | |
| CVE-2026-0095 | Medium | 0.1% | 8.0 | In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlle… | |
| CVE-2026-11072 | Medium | 0.1% | 7.8 | Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 all… | |
| CVE-2026-57012 | Medium | 0.1% | 8.4 | In the Setup Wizard, there is a possible remote package install due to a missing… | |
| CVE-2025-48565 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible way to bypass the cross profile inten… | |
| CVE-2026-21733 | Medium | 0.1% | 7.3 | Software installed and run as a non-privileged user may conduct improper GPU sys… | |
| CVE-2026-9987 | Medium | 0.1% | 7.8 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on… | |
| CVE-2025-48566 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible permission bypass due to a confused d… | |
| CVE-2026-79286 | Medium | 0.1% | 7.4 | Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.… | |
| CVE-2026-28639 | Medium | 0.1% | 7.8 | In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write d… | |
| CVE-2026-11297 | Medium | 0.1% | 7.7 | Insufficient validation of untrusted input in Reader Mode in Google Chrome on An… | |
| CVE-2026-79057 | Medium | 0.1% | 8.1 | Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 al… | |
| CVE-2026-0008 | Medium | 0.1% | 8.4 | In multiple functions of FaceEnroll.kt, there is a possible privilege escalation… | |
| CVE-2025-22424 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible way to reveal images across users due… | |
| CVE-2026-0009 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible tapjacking due to a logic error in th… | |
| CVE-2025-22426 | Medium | 0.1% | 7.8 | In many functions of ComputerEngine.java, there is a possible way to access URIs… | |
| CVE-2025-48652 | Medium | 0.1% | 7.8 | In performPreInstallChecks of InstallRepository.kt, there is a possible way to b… | |
| CVE-2026-0045 | Medium | 0.1% | 7.8 | In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding… | |
| CVE-2026-28658 | Medium | 0.1% | 7.8 | In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a l… | |
| CVE-2026-0077 | Medium | 0.1% | 7.8 | In resumeConfigurationDispatch of ActivityRecord.java, there is a possible backg… | |
| CVE-2026-0087 | Medium | 0.1% | 7.8 | In approvalLevelForDomainInternal of DomainVerificationService.java, there is a … | |
| CVE-2026-56970 | Medium | 0.1% | 8.4 | In multiple locations, there is a possible permission bypass due to a missing pe… | |
| CVE-2026-58678 | Medium | 0.1% | 7.8 | In Bootloader, there is a possible permission bypass due to a logic error in the… | |
| CVE-2026-58679 | Medium | 0.1% | 8.4 | In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overfl… | |
| CVE-2026-58691 | Medium | 0.1% | 8.4 | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper… | |
| CVE-2026-8497 | Medium | 0.1% | 7.4 | Improper certificate validation in the Devolutions Server connection handling in… | |
| CVE-2025-48649 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible way to reset user-selected permission… | |
| CVE-2026-0076 | Medium | 0.1% | 7.8 | In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due… | |
| CVE-2026-0078 | Medium | 0.1% | 7.8 | In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync… | |
| CVE-2026-0088 | Medium | 0.1% | 7.8 | In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a s… | |
| CVE-2026-11035 | Medium | 0.1% | 7.3 | Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to… |