VYPR

Android

by Google

CVEs (8,504)

  • CVE-2026-0086MedJun 1, 2026
    risk 0.44cvss 6.8epss 0.00

    In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0048MedJun 1, 2026
    risk 0.44cvss 6.8epss 0.00

    In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0119MedMar 10, 2026
    risk 0.44cvss 6.8epss 0.00

    In usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memory corruption. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0027MedMar 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-20444MedMar 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In display, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10436995; Issue ID:…

  • CVE-2026-20443MedMar 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10436998; Issue ID: MSV-5722.

  • CVE-2026-20441MedMar 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10432500; Issue ID:…

  • CVE-2026-20440MedMar 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431968; Issue ID:…

  • CVE-2026-20428MedMar 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID:…

  • CVE-2026-20427MedMar 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In display, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue…

  • CVE-2026-20426MedMar 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID:…

  • CVE-2026-20425MedMar 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID:…

  • CVE-2026-20414MedFeb 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10362999; Issue ID:…

  • CVE-2026-20413MedFeb 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10362725; Issue ID:…

  • CVE-2026-20410MedFeb 2, 2026
    risk 0.44cvss 6.7epss 0.00

    In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10362552; Issue ID:…

  • CVE-2025-20807MedJan 6, 2026
    risk 0.44cvss 6.7epss 0.00

    In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114841; Issue ID:…

  • CVE-2025-20806MedJan 6, 2026
    risk 0.44cvss 6.7epss 0.00

    In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114835; Issue ID: MSV-4479.

  • CVE-2025-20805MedJan 6, 2026
    risk 0.44cvss 6.7epss 0.00

    In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114696; Issue ID: MSV-4480.

  • CVE-2025-20804MedJan 6, 2026
    risk 0.44cvss 6.7epss 0.00

    In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10198951; Issue ID: MSV-4503.

  • CVE-2025-20803MedJan 6, 2026
    risk 0.44cvss 6.7epss 0.00

    In dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10199779; Issue ID: MSV-4504.

Page 221 of 426