|
51
|
7.8
-
|
HIGH
Local
|
In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This could lead to local escalation of privilege with no additional …
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-48652
|
cpe:2.3:o:google:android:16.0:qpr2_beta_3 cpe:2.3:o:google:android:16.0:qpr2_beta_2 cpe:2.3:o:google:android:16.0…
|
|
|
|
|
2026-06-3 03:59
2026-06-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
52
|
7.8
-
|
HIGH
Local
|
In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead to local escalation of privilege with no additional execution…
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-48649
|
cpe:2.3:o:google:android:16.0:qpr2_beta_3 cpe:2.3:o:google:android:16.0:qpr2_beta_2 cpe:2.3:o:google:android:16.0…
|
|
|
|
|
2026-06-3 23:35
2026-06-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
53
|
5.5
-
|
MEDIUM
Local
|
In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional execution privileges need…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-48648
|
cpe:2.3:o:google:android:16.0:- cpe:2.3:o:google:android:15.0:* cpe:2.3:o:google:android:14.0:*
|
|
|
|
|
2026-06-3 03:59
2026-06-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
54
|
3.3
-
|
LOW
Local
|
In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclos…
|
NVD-CWE-noinfo
|
CVE-2025-48616
|
cpe:2.3:o:google:android:16.0:qpr2_beta_3 cpe:2.3:o:google:android:16.0:qpr2_beta_2 cpe:2.3:o:google:android:16.0…
|
|
|
|
|
2026-06-3 03:58
2026-06-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
55
|
7.8
-
|
HIGH
Local
|
In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to a confused deputy. This could lead to local escalation of privilege with no ad…
|
CWE-441
Confused Deputy
|
CVE-2025-48570
|
cpe:2.3:o:google:android:14.0:*
|
|
|
|
|
2026-06-3 03:58
2026-06-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
56
|
7.8
-
|
HIGH
Local
|
In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges neede…
|
NVD-CWE-noinfo
|
CVE-2025-32348
|
cpe:2.3:o:google:android:16.0:qpr2_beta_3 cpe:2.3:o:google:android:16.0:qpr2_beta_2 cpe:2.3:o:google:android:16.0…
|
|
|
|
|
2026-06-3 03:50
2026-06-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
57
|
7.8
-
|
HIGH
Local
|
In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This c…
|
CWE-862
Missing Authorization
|
CVE-2025-26418
|
cpe:2.3:o:google:android:15.0:* cpe:2.3:o:google:android:14.0:*
|
|
|
|
|
2026-06-3 23:16
2026-06-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
58
|
7.8
-
|
HIGH
Local
|
In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional exe…
|
CWE-284
Improper Access Control
|
CVE-2025-22426
|
cpe:2.3:o:google:android:16.0:qpr2_beta_3 cpe:2.3:o:google:android:16.0:qpr2_beta_2 cpe:2.3:o:google:android:16.0…
|
|
|
|
|
2026-06-3 23:16
2026-06-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
59
|
7.8
-
|
HIGH
Local
|
In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges…
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2025-22424
|
cpe:2.3:o:google:android:16.0:qpr2_beta_3 cpe:2.3:o:google:android:16.0:qpr2_beta_2 cpe:2.3:o:google:android:16.0…
|
|
|
|
|
2026-06-4 07:16
2026-06-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
60
|
7.5
-
|
HIGH
Network
|
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
|
NVD-CWE-noinfo
|
CVE-2025-71256
|
cpe:2.3:o:google:android:16.0:- cpe:2.3:o:google:android:15.0:* cpe:2.3:o:google:android:14.0:* cpe:2.3:o:goog…
|
|
|
|
|
2026-05-12 00:06
2026-05-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|