Android
This hub aggregates every CVE we track for Android, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
9,211
CVEs tracked
788
Critical
3,964
High
37
In CISA KEV
Severity distribution
MEDIUM4,183HIGH3,964CRITICAL788LOW275
Monthly trend
55
129
58
84
42
17
17
21
12
15
34
190
14
15
116
32
16
107
11
13
127
0
18
203
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Android.
- CVE-2026-58773In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges ne...6.7
- CVE-2026-58767In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileg...6.7
- CVE-2026-58766In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution p...7.8
- CVE-2026-58765In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not nee...6.7
- CVE-2026-58755In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution pri...6.7
- CVE-2026-58751In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed...6.7
- CVE-2026-58747In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed...6.7
- CVE-2026-58744In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed....7.8
- CVE-2026-58739In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileg...6.7
- CVE-2026-58734In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privilege...7.0
- CVE-2026-58731In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privi...6.2
- CVE-2026-58728In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...7.0
- CVE-2026-58726In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User in...6.7
- CVE-2026-58724In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not ...7.0
- CVE-2026-58721In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User inte...4.4
Product normalization is registry-driven with AI assist and human review. How it works