ZeroHour

Vulnerabilities

40 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-48595
Integer Overflow Local Privilege Escalation in Android Framework

CVE-2025-48595 is an integer overflow (CWE-190) in the Android Framework, present in multiple locations, that can be triggered by code already running locally on the device with no additional execution privileges and no user interaction required. A local attacker, such as a malicious or compromised app, who triggers the overflow can achieve code execution with elevated privileges, yielding a local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.4, local attack vector). The flaw affects the Android Framework component of Google's Android operating system, so it applies broadly across the Android device ecosystem; specific affected version ranges were not published in the available data. Google fixed the flaw in its June 2026 Android security update, which patched 124 flaws overall, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-02, with news coverage confirming it is being actively exploited in the wild. No public proof-of-concept is known, but confirmed in-the-wild exploitation makes patching urgent.

Do: Apply Google's June 2026 Android security update (or later) to all Android devices as soon as the OEM build is available, and verify the device's 'Android security patch level' reads June 2026 or later before treating it as remediated. US federal agencies must remediate within the BOD 22-01 timelines per the KEV listing. Because exploitation requires local code execution, prioritize devices on which users can install or run untrusted apps, and use MDM tooling to track patch compliance across managed fleets.

8.42% KEV
  • Google Android
masshundreds of millions of Android devices potentially exposed (news coverage reports millions of affected devices)
CVE-2025-48572
+1 in the same advisory: …48633
Local Privilege Escalation in Android Framework Under Active Exploitation

CVE-2025-48572 is a permissions bypass in multiple locations of the Android Framework that allows activities to be launched from the background in violation of normal permission rules. It is triggered locally — per the CVSS vector, an attacker (typically a malicious or compromised app already on the device) needs only low local privileges, with no user interaction required. Successful exploitation yields local escalation of privilege with high impact on confidentiality, integrity, and availability, giving the attacker elevated control over the device. Android devices running an affected version of the Android Framework are in scope; specific affected version numbers are not given in the source data, and the fix shipped in Google's December 2025 Android security update alongside the related in-the-wild flaw CVE-2025-48633. The bug is being exploited in targeted attacks in the wild — Google described it as 'under targeted exploitation' and CISA added it to the KEV catalog on 2025-12-02 (ransomware use: unknown) — although no public proof-of-concept is known and EPSS remains low at 0.3%.

Do: Apply Google's December 2025 Android security bulletin patches as soon as the OTA update reaches your devices (Pixel and Google-supported models typically receive monthly updates first) and verify the patch level in system update settings. Because exploitation requires an existing local foothold, review and remove untrusted or sideloaded apps on high-value and managed devices. Under CISA KEV / BOD 22-01 requirements, federal agencies must apply the vendor mitigation or discontinue use of affected products within the required timeframe.

7.8
group max
<1% KEV
  • Google Android (Framework component)
massbillions of Android devices (Android runs on 3+ billion active devices, and the Framework component is present on every Android device)
CVE-2025-48543
Use-After-Free in Android Runtime Enables Sandbox Escape and Local Privilege Escalation

CVE-2025-48543 is a use-after-free (CWE-416) in the Android Runtime that exists in multiple code locations and allows an attacker who has already achieved code execution inside the Chrome sandbox to escape and attack the Android system_server process. The trigger requires only local access to the vulnerable component, with no additional execution privileges and no user interaction needed for exploitation. A successful attacker gains local escalation of privilege in the Android system server, making the bug especially useful as a privilege-escalation link in exploit chains against Android devices. Any Android device from Google's platform is in scope per CISA's listing (vendor: Google, product: Android, component: Android Runtime); specific affected version ranges are not enumerated in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-09-04 and Google's related headlines indicate it is being actively exploited in the wild; EPSS currently estimates only a 0.5% probability of exploitation in the next 30 days, and ransomware use is listed as unknown.

Do: Apply Google's Android security updates (September 2025 security bulletin patch level or later) as soon as they are available for your devices, since this flaw is listed in CISA's KEV and reported as exploited in the wild; per KEV required action, federal agencies must follow BOD 22-01 timelines or discontinue use if mitigations are unavailable. Use MDM/EDR tooling to verify device security patch levels, and note that because this is a sandbox-escape-to-system_server bug, it is most dangerous when chained with a browser/renderer exploit, so keeping Chrome/WebView current matters as well.

8.8<1% KEV
  • Google Android (Android Runtime component)
masson the order of billions of devices (Android runs on roughly 3 billion+ active devices worldwide, and the Android Runtime/system_server component is present on…
CVE-2024-56288
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Docs wp-docs allows Stored XSS.This issue

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Docs wp-docs allows Stored XSS.This issue affects WP Docs: from n/a through <= 2.2.1.

NVD description · AI analysis pending
4.8<1%
  • androidbubble wp docs
CVE-2024-12468
The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepicker' parameter in all versions up to, a

The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepicker' parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

NVD description · AI analysis pending
6.1<1%
  • androidbubbles wp datepicker
CVE-2024-12635
The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the 'dir_id' parameter in all versions up to, and including, 2.2.0 due to insuffi

The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the 'dir_id' parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerability was partially patched in version 2.2.0.

NVD description · AI analysis pending
6.5<1%
  • androidbubble wp docs
CVE-2023-30873
Missing Authorization vulnerability in Fahad Mahmood WP Docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs:

Missing Authorization vulnerability in Fahad Mahmood WP Docs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Docs: from n/a through 1.9.8.

NVD description · AI analysis pending
8.8<1%
  • androidbubble wp docs
CVE-2024-43093
Local Privilege Escalation via Unicode Path Filter Bypass in Android Framework

CVE-2024-43093 is a privilege escalation flaw in the Android Framework's ExternalStorageProvider (the component behind the system document/file picker), where the shouldHideDocument function mishandles Unicode normalization, allowing crafted file paths to bypass the filter that hides sensitive directories such as app-private storage (CWE-176). It is triggered locally: an app with no additional execution privileges can exploit it with user interaction, for example when a user selects a file or location through the documents UI. A successful bypass grants unauthorized access to otherwise protected directories and can lead to local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.3, vector AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Any device running the Android Framework is in scope, meaning effectively the entire Android installed base, although the local access and user-interaction requirements limit practical exploitability to targeted scenarios. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-07 and Google has indicated it may be under limited, targeted exploitation; no public proof-of-concept is known, and EPSS currently rates the 30-day exploitation probability at a modest 0.7%, though the KEV listing is the authoritative in-the-wild signal.

Do: Apply Google's Android security updates immediately — the fix is included in the November 2024 Android Security Bulletin (security patch level 2024-11-01) or later — and verify the device's security patch level in Settings; OEM devices (e.g., Samsung) may receive the fix through vendor updates on a lag. Per the CISA KEV required action, treat patching as urgent or apply vendor mitigations, and as an interim measure restrict sideloaded/untrusted app installs and caution users when picking files through the document picker. Ransomware linkage is unknown, and the user-interaction requirement means exploitation is targeted rather than wormable.

7.3<1% KEV
  • Google Android (Android Framework component)
massbillions of Android devices worldwide (Android runs on roughly 70% of global smartphones)
CVE-2024-47321
Missing Authorization vulnerability in Fahad Mahmood WP Datepicker wp-datepicker.This issue affects WP Datepicker:

Missing Authorization vulnerability in Fahad Mahmood WP Datepicker wp-datepicker.This issue affects WP Datepicker: from n/a through <= 2.1.1.

NVD description · AI analysis pending
9.8<1%
  • androidbubbles wp datepicker
CVE-2024-49629
Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation endless-posts-navigation allows Stored XSS.This issue affects Endless

Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation endless-posts-navigation allows Stored XSS.This issue affects Endless Posts Navigation: from n/a through <= 2.2.7.

NVD description · AI analysis pending
6.1<1%
  • androidbubbles endless posts navigation
CVE-2024-44042
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Datepicker wp-datepicker allows Stored XS

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Datepicker wp-datepicker allows Stored XSS.This issue affects WP Datepicker: from n/a through <= 2.1.1.

NVD description · AI analysis pending
4.8<1%
  • androidbubbles wp datepicker
CVE-2024-32896
Local Privilege Escalation in Google Android Pixel Kernel

CVE-2024-32896 is a logic error (CWE-670/CWE-783) in Android code on Google Pixel devices that allows a bypass leading to local escalation of privilege. The flaw is triggered through local access with no additional execution privileges required, and user interaction is needed for exploitation to succeed. A successful attack yields high impact to confidentiality, integrity, and availability on the affected device (CVSS 3.1 base score 7.8), giving an attacker elevated control of the phone. Per CISA's advisory, only Google Pixel devices running Android are affected. The vulnerability is being exploited in the wild: it was added to CISA's KEV catalog on 2024-06-13, and news coverage describes limited, targeted exploitation of the Android kernel flaw as a zero-day, with users urged to install the latest security updates.

Do: Apply the latest Android security updates from Google (June 2024 security patch level or later) to all Pixel devices, per vendor instructions and CISA's required action. Users can verify their patch level under Settings > About phone > Android security update. Given reports of limited, targeted zero-day exploitation, prioritize patching high-risk users and treat the flaw as a post-compromise privilege-escalation risk.

7.83% KEV
  • google Android (Pixel)
masstens of millions of Pixel devices (estimated active Pixel install base; exact count unknown)
CVE-2024-36971
Use-after-free in Linux kernel network dst cache (CVE-2024-36971), exploited on Android

CVE-2024-36971 is a use-after-free (CWE-416) race condition in the Linux kernel networking stack: __dst_negative_advice() clears a socket's cached destination (sk->sk_dst_cache) in the wrong order relative to RCU rules and dst_release(), which can free the destination entry while it is still referenced. The bug is reachable through UDP socket operations, and CISA catalogs the impact as remote code execution in the affected kernel (Android Kernel), although the published CVSS 3.1 vector scores a local attack vector (7.8 High, AV:L). An attacker who triggers the race gains code execution in kernel context, meaning on Android a malicious app could potentially escape its sandbox and take full control of the device, with high impact on confidentiality, integrity, and availability. Affected systems include Android devices running vulnerable kernels and Linux-based systems listed in the CPE data (upstream Linux kernel and Debian Linux), with no specific vulnerable version ranges disclosed in the available data. The flaw is being actively exploited: Google warned of in-the-wild exploitation (the issue was tracked by researcher Clement Lecigne), CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-07, and EPSS estimates a ~2.7% probability of exploitation in the next 30 days; no public PoC is known.

Do: Install Android security updates from Google and device OEMs (Google has already shipped patches) and verify your device's security patch level is current. Debian and other Linux users should update kernel packages to builds containing the upstream fix for the __dst_negative_advice() race. Because CISA added this to KEV on 2024-08-07 with active exploitation, apply vendor mitigations promptly or discontinue use if mitigations are unavailable.

7.83% KEV
  • Linux kernel
  • Debian Linux (linux kernel packages)
  • Google / Android Android kernel
masson the order of billions of Android devices potentially affected pre-patch (upper bound), plus a large installed base across Linux/Debian systems
CVE-2024-31294
Missing Authorization vulnerability in Fahad Mahmood WP Sort Order.This issue affects WP Sort Order:

Missing Authorization vulnerability in Fahad Mahmood WP Sort Order.This issue affects WP Sort Order: from n/a through 1.3.1.

NVD description · AI analysis pending
8.8<1%
  • androidbubble wp sort order
CVE-2024-35696
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Fahad Mahmood WP Docs allows Reflected XSS.This iss

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Fahad Mahmood WP Docs allows Reflected XSS.This issue affects WP Docs: from n/a through 2.1.3.

NVD description · AI analysis pending
6.1<1%
  • androidbubble wp docs
CVE-2024-3895
The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdp_add_new_datepicker_ajax(

The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpdp_add_new_datepicker_ajax() function in all versions up to, and including, 2.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options that can be used for privilege escalation. This was partially patched in 2.0.9 and 2.1.0, and fully patched in 2.1.1.

NVD description · AI analysis pending
8.8<1%
  • androidbubbles wp datepicker
CVE-2024-29748
+1 in the same advisory: …29745
Local Privilege Escalation in Google Pixel (Android), Exploited in the Wild

Google Pixel devices running affected Android software contain a privilege escalation flaw (CVE-2024-29748) caused by a logic error that allows a security bypass. Exploitation is local to the device and requires user interaction, but the attacker needs no additional execution privileges to complete the escalation. A successful exploit grants the attacker elevated privileges on the device with high impact on confidentiality, integrity, and availability. All unpatched Google Android Pixel devices are affected; the source data does not specify exact affected version ranges. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2024-04-04, and press reporting describes Google patching actively exploited Pixel zero-day flaws, with reporting tying the exploitation to forensic/phone-cracking companies.

Do: Update Pixel devices with Google's latest Android security update and verify the Android security patch level is April 2024 or later in Settings > About phone; this is a CISA KEV entry, so apply vendor mitigations promptly or discontinue use per the KEV required action. Because exploitation requires local access and user interaction, restrict device access to untrusted parties and avoid side-loading untrusted apps on unpatched devices. No public proof-of-concept is known, but active exploitation means patching should not wait.

7.8
group max
<1% KEV
  • google Android Pixel (Pixel smartphones, Android OS/firmware)
mass≈tens of millions of Pixel smartphones (estimated active install base; only devices not yet on the vendor's security update are exploitable)
CVE-2023-35674
Local Privilege Escalation in Android Framework (CVE-2023-35674)

CVE-2023-35674 is a privilege escalation flaw in the Android Framework caused by a logic error in the onCreate function of WindowState.java, which allows a background activity to be launched incorrectly. It is triggered by code already running on the device: an app with no special permissions can exploit the logic error, and no user interaction is required for exploitation. A successful attacker gains local escalation of privilege with high impact on the confidentiality, integrity, and availability of the affected device. Any Android device running an unpatched Android Framework build is in scope, and Google addressed the flaw in a monthly Android security update. The vulnerability was actively exploited as a zero-day and was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-13; no public proof-of-concept is known.

Do: Apply the latest monthly Android security update delivered by Google or the device OEM as soon as it is available, and verify each device's Android security patch level reflects the fixed release; no workaround is documented in the available data. As an entry on the CISA KEV catalog, federal and critical-infrastructure organizations are required to apply the vendor fix or discontinue use per the KEV required action. Since exploitation requires code already running locally on the device, prioritize patching devices that install untrusted or third-party apps.

7.83% KEV
  • Google Android (Android Framework)
massbillions of devices (Android runs on roughly 3 billion+ active devices worldwide)
CVE-2023-21237
Information Disclosure via Hidden Foreground Service Notifications on Android 13 Pixels

CVE-2023-21237 is an information disclosure flaw (CWE-200) in the applyRemoteView function of NotificationContentInflater.java on Android 13, where misleading or insufficient UI can cause a foreground service notification to be hidden from the user. A locally installed app with only low privileges can trigger the condition without any user interaction, causing the system not to visibly display the app's foreground service notification. An attacker gains a covert execution context: the user receives no indication that an app or service is running, which Google classifies as local information disclosure because the user is deprived of awareness of activity on their device. Affected users are those with Google Pixel devices running Android 13, per CISA's advisory. The bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-03-05, confirming in-the-wild exploitation, though EPSS currently estimates only a 0.3% probability of exploitation in the next 30 days and no public PoC is known.

Do: Apply Google's latest Pixel/Android monthly security update to all Android 13 Pixel devices, prioritizing fleet patching per the CISA KEV required action, and verify devices report a security patch level that includes this fix. As a detection aid, review installed apps that run foreground services whose notifications are not visible, since hiding the foreground service notification is the core abuse of this flaw. If patching is not possible, follow vendor mitigations per CISA guidance or discontinue use of affected devices.

5.5<1% KEV
  • Google Android (Pixel devices)
massmillions of Pixel devices running Android 13 (a subset of Google's estimated tens-of-millions cumulative Pixel install base)
CVE-2023-29761
An issue found in Sleep v.20230303 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.

An issue found in Sleep v.20230303 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.

NVD description · AI analysis pending
5.5<1% PoC
  • urbanandroid sleep
CVE-2023-29755
+1 in the same advisory: …29756
An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files.

An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files.

NVD description · AI analysis pending
7.8
group max
<1% PoC
  • urbanandroid twilight
CVE-2023-20963
Local Privilege Escalation in Android Framework (WorkSource Parcel Mismatch)

CVE-2023-20963 is a local privilege escalation vulnerability in the Android Framework's WorkSource component, caused by a parcel mismatch (improperly handled parcel data) on devices running Android 11, 12, 12L, and 13. A malicious or compromised app already on the device can trigger the mismatch with no additional execution privileges and no user interaction, making it a low-friction vector once an attacker has any local foothold. Successful exploitation escalates privileges beyond the normal app sandbox - the CVSS 7.8 vector scores high confidentiality, integrity, and availability impact while requiring only low local privileges, indicating substantial system-level access. Any Android device on versions 11 through 13 that has not received the vendor's security patch is potentially affected, which spans a large share of the global smartphone and tablet fleet. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-13 (EPSS currently estimates a 1.5% probability of exploitation in the next 30 days), and related news coverage - including Google's suspension of the Chinese e-commerce app Pinduoduo over malware - links the exploited bug to a broader malware campaign.

Do: Apply the latest Android security updates from your device vendor or OEM as soon as they are issued, prioritizing all devices on Android 11, 12, 12L, or 13 - this is the required action CISA lists for this KEV entry. Until patched, avoid installing apps from untrusted sources, since exploitation requires the attacker to already run code locally on the device. Administrators should inventory Android 11-13 endpoints via MDM/EMM and track the fix by Android bug ID A-220302519.

7.81% KEV
  • google android Android 11, Android 12, Android 12L, and Android 13 (Android Framework component; Android bug ID A-220302519)
mass~1-3+ billion devices (Android 11-13 cover the majority of Google's 3+ billion active Android installs)
CVE-2021-36689
An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decry

An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samourai.dat file. The PIN is 5 to 8 digits, which may be insufficient in this situation.

NVD description · AI analysis pending
5.5<1% PoC
  • samourai-wallet-android project samourai-wallet-android
CVE-2020-36628
A vulnerability classified as critical has been found in Calsign APDE.

A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java of the component ZIP File Handler. The manipulation leads to path traversal. Upgrading to version 0.5.2-pre2-alpha is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216747.

NVD description · AI analysis pending
9.8<1%
  • android processing development environment project android processing development environment
CVE-2022-1820
The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in versions up to, and including, 2.0.2 due to

The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

NVD description · AI analysis pending
6.11%
  • androidbubbles keep backup daily
CVE-2022-23435
decoding.c in android-gif-drawable before 1.2.24 does not limit the maximum length of a comment, leading to denial of service.

decoding.c in android-gif-drawable before 1.2.24 does not limit the maximum length of a comment, leading to denial of service.

NVD description · AI analysis pending
7.51%
  • android-gif-drawable project android-gif-drawable
CVE-2021-1048
+1 in the same advisory: …0920
Use-After-Free Privilege Escalation in Android Kernel (CVE-2021-1048)

CVE-2021-1048 is a use-after-free (CWE-416) in ep_loop_check_proc of eventpoll.c — the Android kernel's epoll event-notification code — that can corrupt kernel memory. A local attacker (e.g., a malicious app with no special permissions) can trigger the flaw, and no user interaction is required, yielding local escalation of privilege to kernel level. Any Android device running an unpatched Android kernel is affected. The flaw is being actively exploited: it is in CISA's Known Exploited Vulnerabilities Catalog (added 2022-05-23) and reporting indicates Google fixed it as a zero-day used in targeted attacks, with coverage tying Android kernel zero-days to Cytrox/Intellexa Predator spyware campaigns. EPSS currently puts the 30-day exploitation probability at ~1.0%, but the KEV listing and in-the-wild targeting make patching urgent.

Do: Apply updates per vendor instructions (CISA KEV required action): install the latest Android security/kernel updates from Google or your device OEM — Google's advisories indicate the complete fix shipped in the February 2022 Android security bulletin (2022-02-05 patch level), following the initial January 2022 fix. Fleet administrators should verify devices' security patch levels and prioritize high-value/targeted users, since observed exploitation has been targeted (spyware-linked) rather than mass-scale. No public PoC is known and ransomware use is unknown, but defenders should hunt for signs of local privilege escalation on unpatched fleets.

7.8
group max
1% KEV
  • Google Android (kernel)
mass≈3 billion Android devices worldwide (Android's global active-device installed base; unpatched share unknown)
CVE-2021-24798
The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it back in the plugin's settings page, leading

The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it back in the plugin's settings page, leading to a Reflected Cross-Site Scripting issue

NVD description · AI analysis pending
6.1<1% PoC
  • androidbubbles wp header images
CVE-2020-8913
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2.

A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the attacker could perform a directory traversal, execute code as the targeted application and access the targeted application's data on the Android device. We recommend all users update Play Core to version 1.7.2 or later.

NVD description · AI analysis pending
8.83% PoC
  • android play core library
CVE-2020-0041
Out-of-Bounds Write in Android Kernel Binder Driver Enables Local Privilege Escalation

CVE-2020-0041 is an out-of-bounds write in the binder_transaction function of the Android kernel's binder.c, caused by an incorrect bounds check in the binder IPC driver. It is triggered locally: code already on the device, such as an unprivileged app or process, can issue a maliciously crafted binder transaction with no user interaction and no additional execution privileges required. A successful exploit escalates a local attacker from app-level privileges to kernel-level code execution, giving full read/write control of the device — the same type of primitive used by rooting malware seen in recent Android threats. Affected products are Android devices running kernel builds without the upstream binder fix; Google is the listed vendor, and because the flaw sits in the shared Android kernel it potentially spans many OEM device models rather than a single product. CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating known exploitation in the wild, though no public PoC is known and EPSS estimates roughly a 3% chance of exploitation in any 30-day window.

Do: Apply the kernel/binder patch by installing your device OEM's latest Android security update, consistent with CISA KEV's required action to apply updates per vendor instructions, and verify the device is on a current security patch level. There is no known mitigation short of patching the binder driver, so prioritize devices that install untrusted apps, where local attackers have an execution foothold. The rooting malware activity in recent headlines is not confirmed in this data to exploit CVE-2020-0041, but patching eliminates the kernel LPE primitive such malware relies on.

7.83% KEV
  • Google Android (kernel, binder driver) Android kernel builds without the upstream binder.c fix; CISA lists 'Android Android Kernel' with no specific kernel version ranges provided in the source data
mass≈ billions of Android devices potentially affected (Android's global active install base is on the order of 3 billion devices)
CVE-2019-2215
Use-After-Free Privilege Escalation in Android Kernel (CVE-2019-2215)

CVE-2019-2215 is a use-after-free flaw (CWE-416) in the Android kernel's binder.c IPC driver that allows privilege escalation from an application to the Linux kernel. Exploitation requires no user interaction, but an attacker must either run a malicious local application or chain the bug with a vulnerability in a network-facing application. Successful exploitation yields kernel-level code execution, effectively rooting the device and giving the attacker full control over apps, data, and communications. Affected parties include Android devices with unpatched kernels (reporting at the time indicated most Android phones were affected), plus products shipping affected Android kernel code, including Google Android, Debian/Ubuntu builds, and NetApp and Huawei offerings. The flaw was publicly disclosed and patched in Android's October 2019 security updates, public proof-of-concept exploits exist, and it is listed in CISA's Known Exploited Vulnerabilities catalog with a high (72.1%) EPSS probability of exploitation; headlines confirm in-the-wild use, including a Google Play app that leveraged it to deliver spyware.

Do: Apply vendor-supplied updates per CISA's required action — for phones and tablets, ensure the device is on the October 2019 Android security patch level or later (check Settings > About phone > Android security patch level) and patch via MDM across your fleet; NetApp, Huawei, Debian, and Ubuntu customers should install their vendors' corresponding kernel updates. Because this is a local privilege escalation with no user interaction required, also patch any network-facing applications that could be chained with it, and hunt for signs of exploitation such as unexpected root or unknown sideloaded/rooting apps on managed devices.

7.872% KEV PoC ×2
  • google android (Android kernel, binder.c)
  • huawei android (Android-based devices)
  • debian linux (Android kernel code)
  • +9 more
massbillions of devices
CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android

A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.

NVD description · AI analysis pending
8.845% PoC
  • whatsapp whatsapp
  • whatsapp android-gif-drawable
CVE-2016-10641
node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.

NVD description · AI analysis pending
8.1<1%
  • node-bsdiff-android project node-bsdiff-android
CVE-2017-1000498
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution

AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution

NVD description · AI analysis pending
7.82%
  • androidsvg project androidsvg
CVE-2017-1002003
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedi

Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.

NVD description · AI analysis pending
9.812% PoC ×2
  • wp2android-turn-wp-site-into-android-app project wp2android-turn-wp-site-into-android-app
CVE-2011-1823
Privilege Escalation to Root via Netlink Spoofing in Android vold Daemon

The vold volume manager daemon in Android trusts messages arriving on a PF_NETLINK socket without authenticating their source, so a local process can send spoofed netlink messages to the daemon. A malicious app running on the device can abuse this trust to have vold execute code on its behalf with elevated privileges. A successful attacker gains root privileges, giving full control of the device and the ability to install software or modify the system. The flaw dates to 2011 and was weaponized in the GingerBreak rooting exploit and the Exploit.AndroidOS.Lotoor malware; CISA added it to the Known Exploited Vulnerabilities catalog on 2022-09-08, confirming in-the-wild exploitation. EPSS currently assigns a 41.6% probability of exploitation in the next 30 days (99th percentile), and the required action is to apply updates per vendor instructions.

Do: Apply updates per vendor instructions as required by CISA's KEV listing, prioritizing legacy devices still running 2011-era Android that cannot receive patches, and retire or isolate them if updates are unavailable. Because this is a local privilege escalation, review devices that permit sideloading or untrusted apps and check rooted devices for signs of the Exploit.AndroidOS.Lotoor malware. Federal agencies should track the KEV remediation deadline.

42% KEV
  • Android OS
masshundreds of millions of Android devices historically (2011-era Android installed base); current count of still-vulnerable legacy devices unknown