Android
9,210 CVEs tracked. 39 of them are in CISA KEV.
This hub aggregates every CVE we track for Android, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Android CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 55 |
| 2024-11 | 129 |
| 2024-12 | 58 |
| 2025-01 | 84 |
| 2025-02 | 42 |
| 2025-03 | 17 |
| 2025-04 | 17 |
| 2025-05 | 21 |
| 2025-06 | 12 |
| 2025-07 | 15 |
| 2025-08 | 34 |
| 2025-09 | 190 |
| 2025-10 | 14 |
| 2025-11 | 15 |
| 2025-12 | 116 |
| 2026-01 | 32 |
| 2026-02 | 16 |
| 2026-03 | 107 |
| 2026-04 | 11 |
| 2026-05 | 13 |
| 2026-06 | 127 |
| 2026-07 | 0 |
| 2026-08 | 18 |
| 2026-09 | 204 |
Severity
How the 9,210 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical788
- High3,962
- Medium4,184
- Low275
Latest CVEs
The 15 most recently published vulnerabilities affecting Android.
- CVE-2026-58773In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges ne...6.7
- CVE-2026-58767In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileg...6.7
- CVE-2026-58766In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution p...7.8
- CVE-2026-58765In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not nee...6.7
- CVE-2026-58755In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution pri...6.7
- CVE-2026-58751In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed...6.7
- CVE-2026-58747In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed...6.7
- CVE-2026-58744In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed....7.8
- CVE-2026-58739In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileg...6.7
- CVE-2026-58734In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privilege...7.0
- CVE-2026-58731In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privi...6.2
- CVE-2026-58728In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...7.0
- CVE-2026-58726In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User in...6.7
- CVE-2026-58724In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not ...7.0
- CVE-2026-58721In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User inte...4.4
Product grouping is registry-driven, with AI assist and human review. How it works