Google Android: vulnerabilidades y CVE
Google Android tiene 8356 vulnerabilidades publicadas, 572 de ellas en los últimos 12 meses. 632 son críticas y 21 figuran en el catálogo de explotación activa de CISA.
CVE8356
Últimos 12 meses572
Críticas632
Explotadas activamente21
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-58704 | Alta (8.8) | 0.59% | ⚠ Explotación activa | 15 sept 2026 | In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User… |
| CVE-2025-48595 | Alta (8.4) | 1.7% | ⚠ Explotación activa | 1 jun 2026 | In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is… |
| CVE-2025-48633 | Media (5.5) | 0.26% | ⚠ Explotación activa | 8 dic 2025 | In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no… |
| CVE-2025-48572 | Alta (7.8) | 0.26% | ⚠ Explotación activa | 8 dic 2025 | In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User… |
| CVE-2025-48543 | Alta (8.8) | 0.54% | ⚠ Explotación activa | 4 sept 2025 | In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges… |
| CVE-2024-50302 | Media (5.5) | 0.81% | ⚠ Explotación activa | 19 nov 2024 | In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during… |
| CVE-2024-43093 | Alta (7.3) | 0.71% | ⚠ Explotación activa | 13 nov 2024 | In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to… |
| CVE-2024-32896 | Alta (7.8) | 3.0% | ⚠ Explotación activa | 13 jun 2024 | there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. |
| CVE-2024-29745 | Media (5.5) | 0.48% | ⚠ Explotación activa | 5 abr 2024 | there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. |
| CVE-2024-29748 | Alta (7.8) | 0.67% | ⚠ Explotación activa | 5 abr 2024 | there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. |
| CVE-2023-21237 | Media (5.5) | 0.27% | ⚠ Explotación activa | 28 jun 2023 | In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no… |
| CVE-2022-22265 | Alta (7.8) | 0.39% | ⚠ Explotación activa | 10 ene 2022 | An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution. |
| CVE-2023-35674 | Alta (7.8) | 2.6% | ⚠ Explotación activa | 11 sept 2023 | In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed.… |
| CVE-2023-20963 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 24 mar 2023 | In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… |
| CVE-2011-1823 | Alta (7.8) | 41% | ⚠ Explotación activa | 9 jun 2011 | The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative… |
| CVE-2021-0920 | Media (6.4) | 0.82% | ⚠ Explotación activa | 15 dic 2021 | In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed… |
| CVE-2021-1048 | Alta (7.8) | 1.0% | ⚠ Explotación activa | 15 dic 2021 | In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction… |
| CVE-2021-39793 | Alta (7.8) | 0.69% | ⚠ Explotación activa | 16 mar 2022 | In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges… |
| CVE-2020-0041 | Alta (7.8) | 3.1% | ⚠ Explotación activa | 10 mar 2020 | In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User… |
| CVE-2020-0069 | Alta (7.8) | 1.4% | ⚠ Explotación activa | 10 mar 2020 | In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-58773 | Media (6.7) | 0.10% | — | 15 sept 2026 | In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction… |
| CVE-2026-58767 | Media (6.7) | 0.10% | — | 15 sept 2026 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User… |
| CVE-2026-58766 | Alta (7.8) | 0.10% | — | 15 sept 2026 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User… |
| CVE-2026-58765 | Media (6.7) | 0.10% | — | 15 sept 2026 | In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. |
| CVE-2026-58755 | Media (6.7) | 0.10% | — | 15 sept 2026 | In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User… |
| CVE-2026-58751 | Media (6.7) | 0.10% | — | 15 sept 2026 | In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is… |
| CVE-2026-58747 | Media (6.7) | 0.10% | — | 15 sept 2026 | In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is… |
| CVE-2026-58744 | Alta (7.8) | 0.10% | — | 15 sept 2026 | In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is… |
| CVE-2026-58739 | Media (6.7) | 0.09% | — | 15 sept 2026 | In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User… |
| CVE-2026-58734 | Alta (7) | 0.07% | — | 15 sept 2026 | In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User… |
| CVE-2026-58731 | Media (6.2) | 0.10% | — | 15 sept 2026 | In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User… |
| CVE-2026-58728 | Alta (7) | 0.07% | — | 15 sept 2026 | In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… |
| CVE-2026-58726 | Media (6.7) | 0.10% | — | 15 sept 2026 | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not… |
| CVE-2026-58724 | Alta (7) | 0.07% | — | 15 sept 2026 | In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for… |
| CVE-2026-58721 | Media (4.4) | 0.09% | — | 15 sept 2026 | In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed… |
| CVE-2026-58718 | Media (6.7) | 0.10% | — | 15 sept 2026 | In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User… |
| CVE-2026-58716 | Media (6.7) | 0.08% | — | 15 sept 2026 | In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed… |
| CVE-2026-58710 | Alta (8.8) | 0.37% | — | 15 sept 2026 | In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User… |
| CVE-2026-58704 | Alta (8.8) | 0.59% | ⚠ Explotación activa | 15 sept 2026 | In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User… |
| CVE-2026-58701 | Alta (7) | 0.07% | — | 15 sept 2026 | In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is… |
| CVE-2026-58699 | Alta (8.4) | 0.10% | — | 15 sept 2026 | In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User… |
| CVE-2026-58698 | Media (6.7) | 0.10% | — | 15 sept 2026 | In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is… |
| CVE-2026-58695 | Alta (7.8) | 0.10% | — | 15 sept 2026 | In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed.… |
| CVE-2026-58691 | Alta (8.4) | 0.10% | — | 15 sept 2026 | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not… |
| CVE-2026-58683 | Alta (8.8) | 0.37% | — | 15 sept 2026 | In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not… |
| CVE-2026-58679 | Alta (8.4) | 0.11% | — | 15 sept 2026 | In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User… |
| CVE-2026-58678 | Alta (7.8) | 0.10% | — | 15 sept 2026 | In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for… |
| CVE-2026-57042 | Media (6.7) | 0.10% | — | 15 sept 2026 | In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction… |
| CVE-2026-57035 | Media (6.7) | 0.10% | — | 15 sept 2026 | In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for… |
| CVE-2026-57014 | Alta (7.8) | 0.10% | — | 15 sept 2026 | In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.