Vulnerabilities (CVE)

Filtered by vendor Google Subscribe
Filtered by product Android
Total 9441 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-79225 1 Google 2 Android, Chrome 2026-08-27 N/A 4.3 MEDIUM
Incorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via UI Interaction. (Chromium security severity: Low)
CVE-2026-79254 1 Google 2 Android, Chrome 2026-08-27 N/A 4.3 MEDIUM
Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79142 1 Google 2 Android, Chrome 2026-08-27 N/A 8.8 HIGH
Buffer overflow in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-79288 1 Google 2 Android, Chrome 2026-08-27 N/A 6.5 MEDIUM
Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
CVE-2026-79129 1 Google 2 Android, Chrome 2026-08-27 N/A 9.6 CRITICAL
Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)
CVE-2026-79132 1 Google 2 Android, Chrome 2026-08-27 N/A 8.3 HIGH
Improper input validation in Input in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79286 1 Google 2 Android, Chrome 2026-08-27 N/A 7.4 HIGH
Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)
CVE-2026-79057 1 Google 2 Android, Chrome 2026-08-27 N/A 8.1 HIGH
Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)
CVE-2026-79008 1 Google 2 Android, Chrome 2026-08-27 N/A 8.3 HIGH
Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78937 1 Google 2 Android, Chrome 2026-08-27 N/A 9.6 CRITICAL
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79044 1 Google 2 Android, Chrome 2026-08-27 N/A 5.3 MEDIUM
Missing authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-79124 1 Google 2 Android, Chrome 2026-08-27 N/A 6.5 MEDIUM
Information leak in Intents in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-79055 1 Google 2 Android, Chrome 2026-08-26 N/A 5.1 MEDIUM
Information leak in Sharing in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Low)
CVE-2026-0013 1 Google 1 Android 2026-08-26 N/A 8.4 HIGH
In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0012 1 Google 1 Android 2026-08-26 N/A 6.2 MEDIUM
In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0011 1 Google 1 Android 2026-08-26 N/A 8.4 HIGH
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0009 1 Google 1 Android 2026-08-26 N/A 7.8 HIGH
In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-76039 1 Google 2 Android, Chrome 2026-08-21 N/A 6.5 MEDIUM
Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
CVE-2026-76046 1 Google 2 Android, Chrome 2026-08-21 N/A 8.3 HIGH
Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-8497 3 Apple, Devolutions, Google 4 Iphone Os, Macos, Password Manager and 1 more 2026-08-21 N/A 7.4 HIGH
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.