Vulnérabilités
Vulnérabilités des apps suivies
6 249 CVE touchent une app ou un OS suivi (toutes sévérités, Android). 48 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 6 249
- Activement exploitées
- 48
- Fenêtre de publication
- 2012-12-26 → 2026-09-17
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-28644
HIGH 7.8
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escal… |
|
CVE-2026-28642
HIGH 7.8
In executeRequest of ActivityStarter.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation… |
|
CVE-2026-28639
HIGH 7.8
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privile… |
|
CVE-2026-28638
LOW 3.3
In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the code. This could lead to local informat… |
|
CVE-2026-28636
HIGH 7.8
In setupLayout of PickActivity.java, there is a possible bypass of the "Install unknown apps" security restriction due to a confused deputy. This could lead to… |
|
CVE-2026-28634
HIGH 7.8
In handleUssdRequest of PhoneInterfaceManager.java, there is a possible way to send a USSD request without permission due to a logic error in the code. This co… |
|
CVE-2026-28633
MEDIUM 5.5
In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to… |
|
CVE-2026-28631
HIGH 7.8
In buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could lead to local escalatio… |
|
CVE-2026-28630
LOW 3.3
In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local information disclosure… |
|
CVE-2026-28627
MEDIUM 4.3
In btm_sec_encrypt_change of btm_sec.cc, there is a possible downgrade attack due to a logic error in the code. This could lead to remote information disclosur… |
|
CVE-2026-28626
HIGH 7.3
In onCreate of SetupPassthroughActivity.java, there is a possible way to launch arbitrary activity due to Intent redirection . This could lead to local escalat… |
|
CVE-2026-28624
HIGH 7.8
In multiple locations, there is a possible read/write access to files without the proper permissions due to a confused deputy. This could lead to local escalat… |
|
CVE-2026-28623
LOW 3.3
In writeToParcel of BleRssiRangingCapabilities.java, there is a possible way to obtain the Bluetooth MAC address due to a missing permission check. This could … |
|
CVE-2026-28622
LOW 3.3
In getQueryBuilderInternal of MediaProvider.java, there is a possible way to retrieve location metadata due to a permissions bypass. This could lead to local i… |
|
CVE-2026-28620
HIGH 7.8
In multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of privilege with no additi… |
|
CVE-2026-28618
HIGH 8.8
In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional executio… |
|
CVE-2026-28617
MEDIUM 5.5
In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no… |
|
CVE-2026-28616
HIGH 7.8
In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy. This could lead to local escalation of privilege wi… |
|
CVE-2026-28614
HIGH 7.8
In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege w… |
|
CVE-2026-28613
HIGH 7.3
In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation. This could lead to local esca… |
|
CVE-2026-28612
HIGH 7.8
In resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. This could lead to … |
|
CVE-2026-28611
HIGH 7.8
In multiple functions of NfcService.java, there is a possible silent payment session hijacking enablement due to a missing permission check. This could lead to… |
|
CVE-2026-28609
HIGH 8.8
In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional … |
|
CVE-2026-28607
HIGH 7.8
In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalatio… |
|
CVE-2026-28606
CRITICAL 9.8
In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalatio… |
|
CVE-2026-28604
HIGH 7.5
In multiple locations, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privil… |
|
CVE-2026-28603
HIGH 7.8
In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy. This could… |
|
CVE-2026-28602
HIGH 7.8
In setClipboardAccessNotificationsEnabledForUser of ClipboardService.java, there is a possible mult-iuser isolation due to a logic error in the code. This coul… |
|
CVE-2026-28600
HIGH 7.8
In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead to local escalation o… |
|
CVE-2026-28599
HIGH 7.8
In addCreatorToken of ActivityManagerService.java, there is a possible Intent Redirection Bypass due to a logic error in the code. This could lead to local esc… |
|
CVE-2026-28596
MEDIUM 5.5
In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local de… |
|
CVE-2026-28594
HIGH 7.8
In multiple locations, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional… |
|
CVE-2026-28593
HIGH 7.8
In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation … |
|
CVE-2026-28590
HIGH 7.8
In multiple locations, there is a possible improper encryption key validation due to a logic error in the code. This could lead to local escalation of privileg… |
|
CVE-2026-28584
MEDIUM 5.5
In createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a logic error in the code. This could le… |
|
CVE-2026-28583
HIGH 7.8
In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. This could lead to loca… |
|
CVE-2026-28582
LOW 3.3
In onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unauthorized access to and modification of device credentials due to a missing permiss… |
|
CVE-2026-28572
HIGH 7.8
In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no… |
|
CVE-2026-0084
HIGH 7.8
In multiple functions of HostEmulationManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local e… |
|
CVE-2026-0065
HIGH 7.8
In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due … |
|
CVE-2026-0054
LOW 3.3
In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a missing permission check. This could lead… |
|
CVE-2026-80097
HIGH 8.6
Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-7477
HIGH 7.8
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows… |
|
CVE-2026-7476
HIGH 7.8
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows… |
|
CVE-2026-5729
HIGH 7.8
Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user proces… |
|
CVE-2026-12387
MEDIUM 5.1
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows… |
|
CVE-2026-12285
MEDIUM 4.0
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows… |
|
CVE-2026-49926
CRITICAL · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2026-49913
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2026-49744
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.