target entity

Android

17 source-linked records in the current knowledge graph.

high

CVE-2025-48595: Android Framework Integer Overflow Vulnerability

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48595EPSS 1.7%AndroidFramework
CISA KEV ↗ · unattributed attribution
high

CVE-2025-48633: Android Framework Information Disclosure Vulnerability

Android Framework contains an unspecified vulnerability that allows for information disclosure. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48633EPSS 0.2%AndroidFramework
CISA KEV ↗ · unattributed attribution
high

CVE-2025-48572: Android Framework Privilege Escalation Vulnerability

Android Framework contains an unspecified vulnerability that allows for privilege escalation. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48572EPSS 0.2%AndroidFramework
CISA KEV ↗ · unattributed attribution
high

CVE-2025-48543: Android Runtime Use-After-Free Vulnerability

Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-48543EPSS 0.5%AndroidRuntime
CISA KEV ↗ · unattributed attribution
high

CVE-2024-36971: Android Kernel Remote Code Execution Vulnerability

Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-36971EPSS 2.7%AndroidKernel
CISA KEV ↗ · unattributed attribution
high

CVE-2024-32896: Android Pixel Privilege Escalation Vulnerability

Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-32896EPSS 3.0%AndroidPixel
CISA KEV ↗ · unattributed attribution
high

CVE-2024-29748: Android Pixel Privilege Escalation Vulnerability

Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-29748EPSS 0.7%AndroidPixel
CISA KEV ↗ · unattributed attribution
high

CVE-2024-29745: Android Pixel Information Disclosure Vulnerability

Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-29745EPSS 0.5%AndroidPixel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-21237: Android Pixel Information Disclosure Vulnerability

Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient, providing a means to hide a foreground service notification. This could enable a local attacker to disclose sensitive information. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-21237EPSS 0.3%AndroidPixel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-20963: Android Framework Privilege Escalation Vulnerability

Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed. Required action: Apply updates per vendor instructions.

CVE-2023-20963EPSS 1.4%AndroidFramework
CISA KEV ↗ · unattributed attribution
high

CVE-2011-1823: Android OS Privilege Escalation Vulnerability

The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and Exploit.AndroidOS.Lotoor. Required action: Apply updates per vendor instructions.

CVE-2011-1823EPSS 41.6%AndroidAndroid OS
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2021-0920: Android Kernel Race Condition Vulnerability

Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2021-0920EPSS 0.8%AndroidKernel
CISA KEV ↗ · unattributed attribution
high

CVE-2019-2215: Android Kernel Use-After-Free Vulnerability

Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu." Required action: Apply updates per vendor instructions.

CVE-2019-2215CVE-2020-0041EPSS 72.1%AndroidAndroid Kernel
CISA KEV ↗ · unattributed attribution
high

CVE-2020-0041: Android Kernel Out-of-Bounds Write Vulnerability

Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu." Required action: Apply updates per vendor instructions.

CVE-2019-2215CVE-2020-0041EPSS 72.1%AndroidAndroid Kernel
CISA KEV ↗ · unattributed attribution