CVE Tools

Android

9,210 CVEs tracked. 39 of them are in CISA KEV.

This hub aggregates every CVE we track for Android, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Android CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Android CVEs per month
MonthCVEs
2024-1055
2024-11129
2024-1258
2025-0184
2025-0242
2025-0317
2025-0417
2025-0521
2025-0612
2025-0715
2025-0834
2025-09190
2025-1014
2025-1115
2025-12116
2026-0132
2026-0216
2026-03107
2026-0411
2026-0513
2026-06127
2026-070
2026-0818
2026-09204

Severity

How the 9,210 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical7889%
  • High3,96243%
  • Medium4,18445%
  • Low2753%

Latest CVEs

The 15 most recently published vulnerabilities affecting Android.

  1. CVE-2026-58773In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges ne...6.7
  2. CVE-2026-58767In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileg...6.7
  3. CVE-2026-58766In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution p...7.8
  4. CVE-2026-58765In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not nee...6.7
  5. CVE-2026-58755In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution pri...6.7
  6. CVE-2026-58751In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed...6.7
  7. CVE-2026-58747In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed...6.7
  8. CVE-2026-58744In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed....7.8
  9. CVE-2026-58739In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileg...6.7
  10. CVE-2026-58734In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privilege...7.0
  11. CVE-2026-58731In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privi...6.2
  12. CVE-2026-58728In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...7.0
  13. CVE-2026-58726In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User in...6.7
  14. CVE-2026-58724In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not ...7.0
  15. CVE-2026-58721In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User inte...4.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store