Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
9126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.28% | — | Google Android | 4/9/2025 | 17/6/2026 | In add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.09% | — | Google Android | 4/9/2025 | 17/6/2026 | In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (8.8) | 0.33% | — | Google Android | 4/9/2025 | 17/6/2026 | In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (5.5) | 0.08% | — | Google Android | 4/9/2025 | 17/6/2026 | In CredentialManagerServiceStub of CredentialManagerService.java, there is a possible way to retrieve candidate credentials due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.09% | — | Google Android | 4/9/2025 | 17/6/2026 | In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.08% | — | Google Android | 4/9/2025 | 17/6/2026 | In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User… | |
| Analizada | Media (5.5) | 0.08% | — | Google Android | 4/9/2025 | 17/6/2026 | In multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.08% | — | Google Android | 4/9/2025 | 17/6/2026 | In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (5.5) | 0.08% | — | Google Android | 4/9/2025 | 17/6/2026 | In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Baja (3.2) | 0.10% | — | Google Android | 4/9/2025 | 17/6/2026 | In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
| Analizada | Media (4.4) | 0.11% | — | Google Android | 4/9/2025 | 17/6/2026 | In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
| Analizada | Media (5.1) | 0.10% | — | Google Android | 4/9/2025 | 17/6/2026 | In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | |
| Analizada | Media (4) | 0.09% | — | Google Android | 4/9/2025 | 17/6/2026 | In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This could lead to local escalation of privilege on versions of Android where android.permission.MANAGE_DEFAULT_APPLICATIONS was not defined with no additional execution privileges… | |
| Analizada | Media (4) | 0.10% | — | Google Android | 4/9/2025 | 17/6/2026 | In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (4) | 0.09% | — | Google Android | 4/9/2025 | 17/6/2026 | In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (4) | 0.10% | — | Google Android | 4/9/2025 | 17/6/2026 | In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (4.4) | 0.09% | — | Google Android | 4/9/2025 | 17/6/2026 | In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (5.1) | 0.10% | — | Google Android | 4/9/2025 | 17/6/2026 | In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. | |
| Analizada | Media (5.1) | 0.22% | 💥 PoC | Google Android | 4/9/2025 | 17/6/2026 | In onCreate of UninstallerActivity.java, there is a possible way to uninstall a different user's app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (4) | 0.10% | — | Google Android | 4/9/2025 | 17/6/2026 | In multiple functions of UserController.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (4) | 0.11% | — | Google Android | 4/9/2025 | 17/6/2026 | In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Media (4) | 0.09% | — | Google Android | 4/9/2025 | 17/6/2026 | In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |
| Analizada | Alta (7.8) | 0.08% | — | Google Android | 4/9/2025 | 30/9/2026 | En onCreate de MediaProjectionPermissionActivity.java, existe una posible forma de otorgar a una aplicación maliciosa un token que permite capacidades de grabación de pantalla no autorizadas debido a una validación de entrada incorrecta. Esto podría conducir a una escalada de privilegios local sin necesidad de… | |
| Analizada | Alta (7.8) | 0.09% | — | Google Android | 4/9/2025 | 30/9/2026 | En setupAccessibilityServices de AccessibilityFragment.java, existe una posible forma de ocultar un servicio de accesibilidad habilitado debido a un error de lógica en el código. Esto podría conducir a una escalada local de privilegios sin necesidad de privilegios de ejecución adicionales. No se necesita interacción… | |
| Analizada | Media (5.5) | 0.07% | — | Google Android | 4/9/2025 | 30/9/2026 | En AndroidManifest.xml, existe una posible forma para que una aplicación monitoree eventos de movimiento debido a un delegado confundido. Esto podría llevar a la revelación de información local sin necesidad de privilegios de ejecución adicionales. No se necesita interacción del usuario para la explotación. |