Vulnerabilities in Google
7,001 resultsCVE-2026-56945HIGHIn VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privilege with no additionaEPSS 0.1%CVE-2025-48586HIGHIn onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from the work profile due to a confused deputy. TEPSS 0.1%CVE-2026-45521LOWIn openFile of AppFuseBridge.java, there is a possible information disclosure due to a missing permission check. This could lead to local inEPSS 0.1%CVE-2025-22424HIGHIn multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escaEPSS 0.1%CVE-2025-48563HIGHIn onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could leadEPSS 0.1%CVE-2024-29744MEDIUMIn tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discEPSS 0.1%CVE-2026-28572HIGHIn onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation oEPSS 0.1%CVE-2025-48573HIGHIn sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service while the app is in the background due tEPSS 0.1%CVE-2023-21249—In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. TEPSS 0.1%CVE-2023-35664—In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to locEPSS 0.1%CVE-2025-26420MEDIUMIn multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission duEPSS 0.1%CVE-2024-29751MEDIUMIn asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information EPSS 0.1%CVE-2018-9390MEDIUMIn procfile_write of gl_proc.c, there is a possible out of bounds read of a
function pointer due to an incorrect bounds check. This couEPSS 0.1%CVE-2023-21165HIGHIn DevmemIntUnmapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local eEPSS 0.1%CVE-2026-28600HIGHIn onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead toEPSS 0.1%CVE-2023-21366—In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecure implementation/design. This could leadEPSS 0.1%CVE-2024-29747MEDIUMIn _dvfs_get_lv of dvfs.c, there is a possible out of bounds read due to a missing null check. This could lead to local information disclosuEPSS 0.1%CVE-2023-21311—In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass. This could lead to lEPSS 0.1%CVE-2023-21232—In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass. This could lead to lEPSS 0.1%CVE-2026-28596MEDIUMIn parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This couEPSS 0.1%