Vulnerabilities in Google

7,003 results
CVE-2026-28578MEDIUMIn multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. ThisEPSS 0.1%CVE-2025-26439HIGHIn getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to be enabled instead ofEPSS 0.1%CVE-2023-21366—In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecure implementation/design. This could leadEPSS 0.1%CVE-2025-36898HIGHThere is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additEPSS 0.1%CVE-2026-28584MEDIUMIn createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a logic error in the EPSS 0.1%CVE-2023-21350—In Media Projection, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informEPSS 0.1%CVE-2026-28633MEDIUMIn initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion.EPSS 0.1%CVE-2023-21230—In onAccessPointChanged of AccessPointPreference.java, there is a possible way for unprivileged apps to receive a broadcast about WiFi accesEPSS 0.1%CVE-2023-21348—In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informatEPSS 0.1%CVE-2025-48536HIGHIn grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to modify secure settingsEPSS 0.1%CVE-2024-40651HIGHIn TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the EPSS 0.1%CVE-2023-21382—In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to a missing permissioEPSS 0.1%CVE-2024-34734HIGHIn onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen EPSS 0.1%CVE-2025-32350HIGHIn maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the ControlsSettingsDialog due to a tapjacking/overlaEPSS 0.1%CVE-2024-22009HIGHIn init_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege wiEPSS 0.1%CVE-2025-48555HIGHIn multiple functions of NotificationStation.java, there is a possible cross-profile information disclosure due to a confused deputy. This cEPSS 0.1%CVE-2025-48547HIGHIn multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead to local escalation EPSS 0.1%CVE-2024-32903HIGHIn prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead EPSS 0.1%CVE-2025-26463MEDIUMIn allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This could lead to a localEPSS 0.1%CVE-2025-32347HIGHIn onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. TEPSS 0.1%