8.8 CVE-2024-31328
In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary...
6.5 CVE-2024-43766
In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid...
8.4 CVE-2025-32313
In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds...
7.8 CVE-2025-48567
In multiple locations, there is a possible bypass of a file path filter designed to prevent access to...
7.4 CVE-2025-48568
In multiple locations, there is a possible lockscreen bypass due to a race condition. This could lead...
8.4 CVE-2025-48574
In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop...
7.4 CVE-2025-48577
In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a race...
7.8 CVE-2025-48578
In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE...
8.4 CVE-2025-48579
In multiple functions of MediaProvider.java, there is a possible external storage write permission bypass...
8.4 CVE-2025-48582
In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission...
6.2 CVE-2025-48585
In multiple functions of ProfilingService.java, there is a possible persistent denial of service due...
6.2 CVE-2025-48587
In multiple functions of ProfilingService.java, there is a possible persistent denial of service due...
8.4 CVE-2025-48602
In exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible...
8.4 CVE-2025-48605
In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic...
9.1 CVE-2025-48609
In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which...
7.8 CVE-2025-48613
In VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original...
8.4 CVE-2025-48619
In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access...
7.4 CVE-2025-48630
In drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due to...
7.3 CVE-2025-48634
In relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing...
7.7 CVE-2025-48635
In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak...
8.4 CVE-2025-48636
In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized...