Vulnérabilités
Vulnérabilités des apps suivies
25 738 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 372 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 738
- Activement exploitées
- 372
- Fenêtre de publication
- 1997-01-01 → 2026-09-17
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-55290
LOW 3.3
In setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap read due to a missing bounds check. This could lead to local information disclosure with … |
|
CVE-2026-55256
MEDIUM 6.5
In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of s… |
|
CVE-2026-49919
HIGH 7.8
In tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escalation of privilege… |
|
CVE-2026-49918
HIGH 7.8
In multiple functions, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional … |
|
CVE-2026-49895
LOW 3.5
In get_eht_operation_channel_width of ieee802_11_common.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (… |
|
CVE-2026-49887
HIGH 7.8
In maybeRemoveInvalidInstallerPackageName of InstallRepository.kt, there is a possible unauthorized app update due to a permissions bypass. This could lead to … |
|
CVE-2026-49884
HIGH 7.8
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privile… |
|
CVE-2026-49882
HIGH 8.8
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no … |
|
CVE-2026-49881
HIGH 7.8
In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalat… |
|
CVE-2026-49879
HIGH 8.8
In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additi… |
|
CVE-2026-45531
HIGH 7.8
In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no a… |
|
CVE-2026-45528
HIGH 7.3
In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to loca… |
|
CVE-2026-45527
MEDIUM 4.3
In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow. This could l… |
|
CVE-2026-45525
LOW 3.3
In multiple locations, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no… |
|
CVE-2026-45521
LOW 3.3
In openFile of AppFuseBridge.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosur… |
|
CVE-2026-45520
HIGH 7.8
In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privileg… |
|
CVE-2026-45519
LOW 3.3
In screenArgsForPermissionCheckIfAny of multiple locations there is a possible risk of unauthorized access due to a confused deputy. This could lead to local i… |
|
CVE-2026-45515
HIGH 7.8
In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lea… |
|
CVE-2026-28671
LOW 3.3
In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local information disclosure … |
|
CVE-2026-28668
HIGH 7.8
In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with… |
|
CVE-2026-28666
HIGH 8.8
In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could… |
|
CVE-2026-28663
HIGH 7.8
In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead t… |
|
CVE-2026-28662
HIGH 8.0
In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/… |
|
CVE-2026-28660
LOW 3.3
In getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code. This could lead to local information disclosure with… |
|
CVE-2026-28658
HIGH 7.8
In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation of privilege with n… |
|
CVE-2026-28657
HIGH 7.8
In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to lo… |
|
CVE-2026-28656
HIGH 7.3
In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of … |
|
CVE-2026-28655
HIGH 7.8
In multiple functions of RemoteViews.java, there is a possible background activity launch bypass due to a logic error in the code. This could lead to local esc… |
|
CVE-2026-28653
HIGH 7.8
In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with n… |
|
CVE-2026-28652
LOW 3.1
In multiple functions of RangingServiceImpl.java, there is a possible MITM due to a missing permission check. This could lead to remote information disclosure … |
|
CVE-2026-28650
HIGH 7.8
In setHiddenWhileSuspended of WindowState.java, there is a possible overlay bypass due to a logic error in the code. This could lead to local escalation of pri… |
|
CVE-2026-28644
HIGH 7.8
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escal… |
|
CVE-2026-28642
HIGH 7.8
In executeRequest of ActivityStarter.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation… |
|
CVE-2026-28639
HIGH 7.8
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privile… |
|
CVE-2026-28638
LOW 3.3
In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the code. This could lead to local informat… |
|
CVE-2026-28636
HIGH 7.8
In setupLayout of PickActivity.java, there is a possible bypass of the "Install unknown apps" security restriction due to a confused deputy. This could lead to… |
|
CVE-2026-28634
HIGH 7.8
In handleUssdRequest of PhoneInterfaceManager.java, there is a possible way to send a USSD request without permission due to a logic error in the code. This co… |
|
CVE-2026-28633
MEDIUM 5.5
In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to… |
|
CVE-2026-28631
HIGH 7.8
In buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could lead to local escalatio… |
|
CVE-2026-28630
LOW 3.3
In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local information disclosure… |
|
CVE-2026-28627
MEDIUM 4.3
In btm_sec_encrypt_change of btm_sec.cc, there is a possible downgrade attack due to a logic error in the code. This could lead to remote information disclosur… |
|
CVE-2026-28626
HIGH 7.3
In onCreate of SetupPassthroughActivity.java, there is a possible way to launch arbitrary activity due to Intent redirection . This could lead to local escalat… |
|
CVE-2026-28624
HIGH 7.8
In multiple locations, there is a possible read/write access to files without the proper permissions due to a confused deputy. This could lead to local escalat… |
|
CVE-2026-28623
LOW 3.3
In writeToParcel of BleRssiRangingCapabilities.java, there is a possible way to obtain the Bluetooth MAC address due to a missing permission check. This could … |
|
CVE-2026-28622
LOW 3.3
In getQueryBuilderInternal of MediaProvider.java, there is a possible way to retrieve location metadata due to a permissions bypass. This could lead to local i… |
|
CVE-2026-28620
HIGH 7.8
In multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of privilege with no additi… |
|
CVE-2026-28618
HIGH 8.8
In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional executio… |
|
CVE-2026-28617
MEDIUM 5.5
In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no… |
|
CVE-2026-28616
HIGH 7.8
In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy. This could lead to local escalation of privilege wi… |
|
CVE-2026-28614
HIGH 7.8
In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege w… |