VYPR

Android

by Google

CVEs (8,504)

  • CVE-2022-24929MedMar 10, 2022
    risk 0.27cvss 4.1epss 0.00

    Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.

  • CVE-2022-20032MedFeb 9, 2022
    risk 0.27cvss 4.1epss 0.00

    In vow driver, there is a possible memory corruption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05852822; Issue ID: ALPS05852822.

  • CVE-2021-39648MedDec 15, 2021
    risk 0.27cvss 4.1epss 0.00

    In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-25476MedOct 6, 2021
    risk 0.27cvss 4.1epss 0.00

    An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass the ASLR protection mechanism in TEE.

  • CVE-2020-0199MedJun 11, 2020
    risk 0.27cvss 4.1epss 0.00

    In TimeCheck::TimeCheckThread::threadLoop of TimeCheck.cpp, there is a possible use-after-free due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2017-13238MedFeb 12, 2018
    risk 0.27cvss 4.2epss 0.00

    In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2026-28581MedJun 1, 2026
    risk 0.26cvss 4.0epss 0.00

    In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileges needed. User interaction is null for exploitation.

  • CVE-2026-0108MedMar 10, 2026
    risk 0.26cvss 4.0epss 0.00

    The register protection of the PowerVR GPU is incorrectly configured. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-0024MedMar 2, 2026
    risk 0.26cvss 4.0epss 0.00

    In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of media due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not…

  • CVE-2025-22415MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In android_app of Android.bp, there is a possible way to launch any activity as a system user. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-49731MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new Pixel Watch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2025-48528MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-48526MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActivity in another profile due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2025-26425MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This could lead to local escalation of privilege on versions of Android where android.permission.MANAGE_DEFAULT_APPLICATIONS was not defined with…

  • CVE-2025-26424MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-26422MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-26421MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-0077MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In multiple functions of UserController.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-49739MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35657MedSep 4, 2025
    risk 0.26cvss 4.0epss 0.00

    In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Page 401 of 426