Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-0133

In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0132

In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0131

In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0130

In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
LOW
Conflicts
1

CVE-2026-0129

In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
LOW
Conflicts
1

CVE-2026-0128

In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
LOW
Conflicts
1

CVE-2026-0127

In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This could lead to remote denial of service causing a communication processor crash with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0126

In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0125

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0124

There is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
0

CVE-2026-0123

In EfwApTransport::ProcessRxRing of efw_ap_transport.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0122

In multiple places, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0121

In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
LOW
Conflicts
1

CVE-2026-0120

In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0119

In usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memory corruption. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0118

In oobconfig, there is a possible bypass of carrier restrictions due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0117

In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0116

In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0115

In Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could lead to physical information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
LOW
Conflicts
1

CVE-2026-0114

In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0113

In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0112

In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0111

In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0110

In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0109

In dhd_tcpdata_info_get of dhd_ip.c, there is a possible Denial of Service due to a precondition check failure. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0108

The register protection of the PowerVR GPU is incorrectly configured. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0107

In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0106

In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0102

Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Edge (Chromium-based)
Provider severity
LOW
Conflicts
0

CVE-2026-0100

In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0099

In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0098

In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0097

In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0096

In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0095

In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0094

In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0093

In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0092

In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0091

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0089

In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0088

In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0087

In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1

CVE-2026-0086

In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0085

In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0083

In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0082

In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0081

In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
CRITICAL
Conflicts
1

CVE-2026-0080

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0079

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
MEDIUM
Conflicts
1

CVE-2026-0078

In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

PUBLISHED
Vendor
Google
Product
Android
Provider severity
HIGH
Conflicts
1