« Volver al listado

Google

Google Android: vulnerabilidades y CVE

Google Android tiene 8356 vulnerabilidades publicadas, 572 de ellas en los últimos 12 meses. 632 son críticas y 21 figuran en el catálogo de explotación activa de CISA.

CVE8356
Últimos 12 meses572
Críticas632
Explotadas activamente21

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-58704Alta (8.8)0.59%⚠ Explotación activa15 sept 2026
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User…
CVE-2025-48595Alta (8.4)1.7%⚠ Explotación activa1 jun 2026
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…
CVE-2025-48633Media (5.5)0.26%⚠ Explotación activa8 dic 2025
In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no…
CVE-2025-48572Alta (7.8)0.26%⚠ Explotación activa8 dic 2025
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User…
CVE-2025-48543Alta (8.8)0.54%⚠ Explotación activa4 sept 2025
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to local escalation of privilege with no additional execution privileges…
CVE-2024-50302Media (5.5)0.81%⚠ Explotación activa19 nov 2024
In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during…
CVE-2024-43093Alta (7.3)0.71%⚠ Explotación activa13 nov 2024
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to…
CVE-2024-32896Alta (7.8)3.0%⚠ Explotación activa13 jun 2024
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
CVE-2024-29745Media (5.5)0.48%⚠ Explotación activa5 abr 2024
there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-29748Alta (7.8)0.67%⚠ Explotación activa5 abr 2024
there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
CVE-2023-21237Media (5.5)0.27%⚠ Explotación activa28 jun 2023
In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or insufficient UI. This could lead to local information disclosure with no…
CVE-2022-22265Alta (7.8)0.39%⚠ Explotación activa10 ene 2022
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
CVE-2023-35674Alta (7.8)2.6%⚠ Explotación activa11 sept 2023
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed.…
CVE-2023-20963Alta (7.8)1.5%⚠ Explotación activa24 mar 2023
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
CVE-2011-1823Alta (7.8)41%⚠ Explotación activa9 jun 2011
The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative…
CVE-2021-0920Media (6.4)0.82%⚠ Explotación activa15 dic 2021
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed…
CVE-2021-1048Alta (7.8)1.0%⚠ Explotación activa15 dic 2021
In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…
CVE-2021-39793Alta (7.8)0.69%⚠ Explotación activa16 mar 2022
In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges…
CVE-2020-0041Alta (7.8)3.1%⚠ Explotación activa10 mar 2020
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User…
CVE-2020-0069Alta (7.8)1.4%⚠ Explotación activa10 mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-58773Media (6.7)0.10%—15 sept 2026
In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction…
CVE-2026-58767Media (6.7)0.10%—15 sept 2026
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User…
CVE-2026-58766Alta (7.8)0.10%—15 sept 2026
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User…
CVE-2026-58765Media (6.7)0.10%—15 sept 2026
In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-58755Media (6.7)0.10%—15 sept 2026
In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User…
CVE-2026-58751Media (6.7)0.10%—15 sept 2026
In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is…
CVE-2026-58747Media (6.7)0.10%—15 sept 2026
In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is…
CVE-2026-58744Alta (7.8)0.10%—15 sept 2026
In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…
CVE-2026-58739Media (6.7)0.09%—15 sept 2026
In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User…
CVE-2026-58734Alta (7)0.07%—15 sept 2026
In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User…
CVE-2026-58731Media (6.2)0.10%—15 sept 2026
In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User…
CVE-2026-58728Alta (7)0.07%—15 sept 2026
In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
CVE-2026-58726Media (6.7)0.10%—15 sept 2026
In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not…
CVE-2026-58724Alta (7)0.07%—15 sept 2026
In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…
CVE-2026-58721Media (4.4)0.09%—15 sept 2026
In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed…
CVE-2026-58718Media (6.7)0.10%—15 sept 2026
In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User…
CVE-2026-58716Media (6.7)0.08%—15 sept 2026
In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed…
CVE-2026-58710Alta (8.8)0.37%—15 sept 2026
In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User…
CVE-2026-58704Alta (8.8)0.59%⚠ Explotación activa15 sept 2026
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User…
CVE-2026-58701Alta (7)0.07%—15 sept 2026
In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is…
CVE-2026-58699Alta (8.4)0.10%—15 sept 2026
In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User…
CVE-2026-58698Media (6.7)0.10%—15 sept 2026
In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is…
CVE-2026-58695Alta (7.8)0.10%—15 sept 2026
In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed.…
CVE-2026-58691Alta (8.4)0.10%—15 sept 2026
In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
CVE-2026-58683Alta (8.8)0.37%—15 sept 2026
In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not…
CVE-2026-58679Alta (8.4)0.11%—15 sept 2026
In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User…
CVE-2026-58678Alta (7.8)0.10%—15 sept 2026
In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…
CVE-2026-57042Media (6.7)0.10%—15 sept 2026
In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction…
CVE-2026-57035Media (6.7)0.10%—15 sept 2026
In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…
CVE-2026-57014Alta (7.8)0.10%—15 sept 2026
In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation19
  2. T1005 Data from Local System4
  3. T1059.004 Unix Shell4
  4. T1059 Command and Scripting Interpreter3
  5. T1059.007 JavaScript2
  6. T1078 Valid Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Google