Android Vulnerabilities
Android is Google's open-source mobile operating system, published through the Android Open Source Project, and KEV entries cover its framework, kernel and Pixel device components. The database tracks 17 Android CVE records. CISA lists 17 of them as exploited in the wild, most recently on 2026-06-02. The most affected products are Framework, Pixel, Kernel.
Recently Exploited Android CVEs
Android Framework Integer Overflow Vulnerability
Android Framework Information Disclosure Vulnerability
Android Framework Privilege Escalation Vulnerability
Android Runtime Use-After-Free Vulnerability
Android Framework Privilege Escalation Vulnerability
net: fix __dst_negative_advice() race
Affected Products
6 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Framework | 6 | 6 | 2026-06-02 |
| Pixel | 4 | 4 | 2024-06-13 |
| Kernel | 3 | 3 | 2024-08-07 |
| Android Kernel | 2 | 2 | 2021-11-03 |
| Android OS | 1 | 1 | 2022-09-08 |
| Runtime | 1 | 1 | 2025-09-04 |
Security Advisories
All Android CVEs
17 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-48595 | Android Framework Integer Overflow Vulnerability | 8.4 | 1.7% | KEV | 2026-06-01 | |
| CVE-2025-48633 | Android Framework Information Disclosure Vulnerability | 5.5 | 0.3% | KEV | 2025-12-08 | |
| CVE-2025-48572 | Android Framework Privilege Escalation Vulnerability | 7.8 | 0.3% | KEV | 2025-12-08 | |
| CVE-2025-48543 | Android Runtime Use-After-Free Vulnerability | 8.8 | 0.5% | KEV | 2025-09-04 | |
| CVE-2024-43093 | Android Framework Privilege Escalation Vulnerability | 7.3 | 0.7% | KEV | 2024-11-13 | |
| CVE-2024-36971 | net: fix __dst_negative_advice() race | Linux | 7.8 | 2.7% | KEV | 2024-06-10 |
| CVE-2024-32896 | Android Pixel Privilege Escalation Vulnerability | 8.1 | 3.0% | KEV | 2024-06-13 | |
| CVE-2024-29748 | Android Pixel Privilege Escalation Vulnerability | 7.8 | 0.7% | KEV | 2024-04-05 | |
| CVE-2024-29745 | Android Pixel Information Disclosure Vulnerability | 5.5 | 0.5% | KEV | 2024-04-05 | |
| CVE-2023-21237 | Android Pixel Information Disclosure Vulnerability | - | 6.2 | 0.3% | KEV | 2023-06-28 |
| CVE-2023-35674 | Android Framework Privilege Escalation Vulnerability | 8.8 | 2.6% | KEV | 2023-09-11 | |
| CVE-2023-20963 | Android Framework Privilege Escalation Vulnerability | - | 7.8 | 1.5% | KEV | 2023-03-24 |
| CVE-2011-1823 | Android OS Privilege Escalation Vulnerability | - | 7.8 | 41.4% | KEV | 2011-06-09 |
| CVE-2021-1048 | Android Kernel Use-After-Free Vulnerability | - | 7.8 | 1.0% | KEV | 2021-12-15 |
| CVE-2021-0920 | Android Kernel Race Condition Vulnerability | - | 6.4 | 0.9% | KEV | 2021-12-15 |
| CVE-2019-2215 | Android Kernel Use-After-Free Vulnerability | - | 7.8 | 72.1% | KEV | 2019-10-11 |
| CVE-2020-0041 | Android Kernel Out-of-Bounds Write Vulnerability | - | 7.8 | 3.1% | KEV | 2020-03-10 |
Frequently Asked Questions
How many Android vulnerabilities are actively exploited?→
17 Android CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-06-02.
Which Android products have the most exploited vulnerabilities?→
- +Framework: 6 CVEs (6 in KEV)
- +Pixel: 4 CVEs (4 in KEV)
- +Kernel: 3 CVEs (3 in KEV)
- +Android Kernel: 2 CVEs (2 in KEV)
- +Android OS: 1 CVE (1 in KEV)
Where does Android publish security advisories?→
Android publishes security advisories at https://source.android.com/docs/security/bulletin. Check the vendor advisory for fixed versions and workarounds before applying updates.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Android, MITRE, CISA, or FIRST.