VYPR

Android

by Google

CVEs (8,504)

  • CVE-2025-48645HigMar 2, 2026
    risk 0.51cvss 7.8epss 0.00

    In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-48613HigMar 2, 2026
    risk 0.51cvss 7.8epss 0.00

    In VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previously signed with the same key. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

  • CVE-2025-48578HigMar 2, 2026
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for…

  • CVE-2025-48567HigMar 2, 2026
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction…

  • CVE-2026-20412HigFeb 2, 2026
    risk 0.51cvss 7.8epss 0.00

    In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10351676; Issue…

  • CVE-2026-20411HigFeb 2, 2026
    risk 0.51cvss 7.8epss 0.00

    In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10351676; Issue ID: MSV-5737.

  • CVE-2026-20409HigFeb 2, 2026
    risk 0.51cvss 7.8epss 0.00

    In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10363246; Issue ID:…

  • CVE-2025-48647HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-20800HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10267349; Issue ID:…

  • CVE-2025-20799HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10274607; Issue ID: MSV-5049.

  • CVE-2025-20798HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID:…

  • CVE-2025-20797HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID:…

  • CVE-2025-20796HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10314745; Issue ID:…

  • CVE-2025-20795HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10276761; Issue…

  • CVE-2025-20781HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182914; Issue ID: MSV-4699.

  • CVE-2025-20780HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184061; Issue ID: MSV-4712.

  • CVE-2025-20778HigJan 6, 2026
    risk 0.51cvss 7.8epss 0.00

    In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184870; Issue ID:…

  • CVE-2025-36936HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-36935HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-36932HigDec 11, 2025
    risk 0.51cvss 7.8epss 0.00

    In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

Page 60 of 426