{"schema_version":1,"title":"Google Android vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 359 vulnerabilities in Google Android: 0 in the last 7 days and 245 in the last 90 days, 43 of them critical and 19 exploited in the wild. The most recent, CVE-2026-93384, was published on 17 September 2026.","url":"https://junglewise.ai/threats/technologies/android","json_url":"https://junglewise.ai/threats/technologies/android.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/android","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":135,"all_time":359,"critical":43,"exploited":19,"last_7_days":0,"last_30_days":210,"last_90_days":245,"last_365_days":337},"latest":[{"cve":"CVE-2026-93384","cvss":3.7,"epss":0.0025,"slug":"cve-2026-93384-google-chrome-server-side-request-forgery-in-omnibox-on-android","title":"Google Chrome server-side request forgery in Omnibox on Android","severity":"low","exploited":false,"published_at":"2026-09-17T21:17:55.743+00:00","url":"https://junglewise.ai/threats/cve-2026-93384-google-chrome-server-side-request-forgery-in-omnibox-on-android"},{"cve":"CVE-2026-93374","cvss":9.6,"epss":0.0041,"slug":"cve-2026-93374-google-chrome-use-after-free-in-dawn-on-android","title":"Google Chrome use-after-free in Dawn on Android","severity":"critical","exploited":false,"published_at":"2026-09-17T21:17:54.42+00:00","url":"https://junglewise.ai/threats/cve-2026-93374-google-chrome-use-after-free-in-dawn-on-android"},{"cve":"CVE-2026-93372","cvss":9.6,"epss":0.0045,"slug":"cve-2026-93372-google-chrome-buffer-overflow-in-webgl","title":"Google Chrome buffer overflow in WebGL","severity":"critical","exploited":false,"published_at":"2026-09-17T21:17:54.18+00:00","url":"https://junglewise.ai/threats/cve-2026-93372-google-chrome-buffer-overflow-in-webgl"},{"cve":"CVE-2026-91726","cvss":4.7,"epss":0.0027,"slug":"cve-2026-91726-google-chrome-webgl-out-of-bounds-read-on-android","title":"Google Chrome WebGL out-of-bounds read on Android","severity":"medium","exploited":false,"published_at":"2026-09-15T21:16:45.85+00:00","url":"https://junglewise.ai/threats/cve-2026-91726-google-chrome-webgl-out-of-bounds-read-on-android"},{"cve":"CVE-2026-91717","cvss":5.1,"epss":0.0009,"slug":"cve-2026-91717-google-chrome-missing-authorization-in-android-content-access","title":"Google Chrome missing authorization in Android content access","severity":"medium","exploited":false,"published_at":"2026-09-15T21:16:44.69+00:00","url":"https://junglewise.ai/threats/cve-2026-91717-google-chrome-missing-authorization-in-android-content-access"},{"cve":"CVE-2026-58773","cvss":6.7,"epss":0.001,"slug":"cve-2026-58773-google-pixel-kernel-out-of-bounds-write-in-gnss-image-loading","title":"Google Pixel kernel out-of-bounds write in GNSS image loading","severity":"medium","exploited":false,"published_at":"2026-09-15T19:17:34.123+00:00","url":"https://junglewise.ai/threats/cve-2026-58773-google-pixel-kernel-out-of-bounds-write-in-gnss-image-loading"},{"cve":"CVE-2026-58767","cvss":6.7,"epss":0.001,"slug":"cve-2026-58767-arm-smmu-v3-privilege-escalation-in-arm-smmu-v3-c","title":"ARM SMMU v3 privilege escalation in arm-smmu-v3.c","severity":"medium","exploited":false,"published_at":"2026-09-15T19:17:34.023+00:00","url":"https://junglewise.ai/threats/cve-2026-58767-arm-smmu-v3-privilege-escalation-in-arm-smmu-v3-c"},{"cve":"CVE-2026-58766","cvss":7.8,"epss":0.001,"slug":"cve-2026-58766-arm-smmu-v3-privilege-escalation-due-to-logic-error","title":"ARM SMMU-v3 privilege escalation due to logic error","severity":"high","exploited":false,"published_at":"2026-09-15T19:17:33.927+00:00","url":"https://junglewise.ai/threats/cve-2026-58766-arm-smmu-v3-privilege-escalation-due-to-logic-error"},{"cve":"CVE-2026-58765","cvss":6.7,"epss":0.001,"slug":"cve-2026-58765-google-pixel-gpu-permission-bypass-via-logic-error","title":"Google Pixel GPU permission bypass via logic error","severity":"medium","exploited":false,"published_at":"2026-09-15T19:17:33.827+00:00","url":"https://junglewise.ai/threats/cve-2026-58765-google-pixel-gpu-permission-bypass-via-logic-error"},{"cve":"CVE-2026-58755","cvss":6.7,"epss":0.001,"slug":"cve-2026-58755-arm-smmu-v3-privilege-escalation-in-nested-ste-installation","title":"ARM SMMU v3 privilege escalation in nested STE installation","severity":"medium","exploited":false,"published_at":"2026-09-15T19:17:33.73+00:00","url":"https://junglewise.ai/threats/cve-2026-58755-arm-smmu-v3-privilege-escalation-in-nested-ste-installation"},{"cve":"CVE-2026-58751","cvss":6.7,"epss":0.001,"slug":"cve-2026-58751-arm-smmu-v3-use-after-free-in-arm-smmu-v3-c","title":"ARM SMMU v3 use-after-free in arm-smmu-v3.c","severity":"medium","exploited":false,"published_at":"2026-09-15T19:17:33.63+00:00","url":"https://junglewise.ai/threats/cve-2026-58751-arm-smmu-v3-use-after-free-in-arm-smmu-v3-c"},{"cve":"CVE-2026-58747","cvss":6.7,"epss":0.001,"slug":"cve-2026-58747-arm-smmu-v3-permission-bypass-in-smmu-detach-dev","title":"ARM SMMU v3 permission bypass in smmu_detach_dev","severity":"medium","exploited":false,"published_at":"2026-09-15T19:17:33.537+00:00","url":"https://junglewise.ai/threats/cve-2026-58747-arm-smmu-v3-permission-bypass-in-smmu-detach-dev"},{"cve":"CVE-2026-58744","cvss":7.8,"epss":0.001,"slug":"cve-2026-58744-google-pixel-privilege-escalation-in-multiple-kernel-components","title":"Google Pixel privilege escalation in multiple kernel components","severity":"high","exploited":false,"published_at":"2026-09-15T19:17:33.44+00:00","url":"https://junglewise.ai/threats/cve-2026-58744-google-pixel-privilege-escalation-in-multiple-kernel-components"},{"cve":"CVE-2026-58739","cvss":6.7,"epss":0.0009,"slug":"cve-2026-58739-google-pixel-gdmc-confused-deputy-privilege-escalation","title":"Google Pixel GDMC confused deputy privilege escalation","severity":"medium","exploited":false,"published_at":"2026-09-15T19:17:33.343+00:00","url":"https://junglewise.ai/threats/cve-2026-58739-google-pixel-gdmc-confused-deputy-privilege-escalation"},{"cve":"CVE-2026-58734","cvss":7,"epss":0.0007,"slug":"cve-2026-58734-google-pixel-gdmc-out-of-bounds-write-due-to-race-condition","title":"Google Pixel GDMC out-of-bounds write due to race condition","severity":"high","exploited":false,"published_at":"2026-09-15T19:17:33.247+00:00","url":"https://junglewise.ai/threats/cve-2026-58734-google-pixel-gdmc-out-of-bounds-write-due-to-race-condition"},{"cve":"CVE-2026-58728","cvss":7,"epss":0.0007,"slug":"cve-2026-58728-arm64-tlbi-memory-corruption-in-trusty-kernel","title":"ARM64_TLBI memory corruption in Trusty kernel","severity":"high","exploited":false,"published_at":"2026-09-15T19:17:33.05+00:00","url":"https://junglewise.ai/threats/cve-2026-58728-arm64-tlbi-memory-corruption-in-trusty-kernel"},{"cve":"CVE-2026-58726","cvss":6.7,"epss":0.001,"slug":"cve-2026-58726-google-pixel-gpca-permission-bypass-in-fsmreleasekey","title":"Google Pixel GPCA permission bypass in FsmReleaseKey","severity":"medium","exploited":false,"published_at":"2026-09-15T19:17:32.95+00:00","url":"https://junglewise.ai/threats/cve-2026-58726-google-pixel-gpca-permission-bypass-in-fsmreleasekey"},{"cve":"CVE-2026-58724","cvss":7,"epss":0.0007,"slug":"cve-2026-58724-google-pixel-kernel-use-after-free-in-race-condition","title":"Google Pixel kernel use-after-free in race condition","severity":"high","exploited":false,"published_at":"2026-09-15T19:17:32.853+00:00","url":"https://junglewise.ai/threats/cve-2026-58724-google-pixel-kernel-use-after-free-in-race-condition"},{"cve":"CVE-2026-58721","cvss":4.4,"epss":0.0009,"slug":"cve-2026-58721-google-pixel-uninitialized-memory-information-disclosure-in-gsa","title":"Google Pixel uninitialized memory information disclosure in GSA","severity":"medium","exploited":false,"published_at":"2026-09-15T19:17:32.753+00:00","url":"https://junglewise.ai/threats/cve-2026-58721-google-pixel-uninitialized-memory-information-disclosure-in-gsa"},{"cve":"CVE-2026-58718","cvss":6.7,"epss":0.001,"slug":"cve-2026-58718-arm-smmu-v3-privilege-escalation-in-smmu-detach-dev-nested","title":"ARM SMMU v3 privilege escalation in smmu_detach_dev_nested","severity":"medium","exploited":false,"published_at":"2026-09-15T19:17:32.65+00:00","url":"https://junglewise.ai/threats/cve-2026-58718-arm-smmu-v3-privilege-escalation-in-smmu-detach-dev-nested"},{"cve":"CVE-2026-58716","cvss":6.7,"epss":0.0008,"slug":"cve-2026-58716-google-pixel-gsa-privilege-escalation-via-toctou-race-condition","title":"Google Pixel GSA privilege escalation via TOCTOU race condition","severity":"medium","exploited":false,"published_at":"2026-09-15T19:17:32.55+00:00","url":"https://junglewise.ai/threats/cve-2026-58716-google-pixel-gsa-privilege-escalation-via-toctou-race-condition"},{"cve":"CVE-2026-58710","cvss":8.8,"epss":0.0037,"slug":"cve-2026-58710-google-pixel-bigocean-out-of-bounds-write-in-film-grain-decoding","title":"Google Pixel BigOcean out-of-bounds write in film grain decoding","severity":"high","exploited":false,"published_at":"2026-09-15T19:17:32.453+00:00","url":"https://junglewise.ai/threats/cve-2026-58710-google-pixel-bigocean-out-of-bounds-write-in-film-grain-decoding"},{"cve":"CVE-2026-58704","cvss":8.8,"epss":0.0059,"slug":"cve-2026-58704-google-pixel-improper-authorization-in-cellular-modem","title":"In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) esc","severity":"critical","exploited":true,"published_at":"2026-09-15T19:17:32.297+00:00","url":"https://junglewise.ai/threats/cve-2026-58704-google-pixel-improper-authorization-in-cellular-modem"},{"cve":"CVE-2026-58701","cvss":7,"epss":0.0007,"slug":"cve-2026-58701-google-trusty-out-of-bounds-write-via-race-condition","title":"Google Trusty out-of-bounds write via race condition","severity":"high","exploited":false,"published_at":"2026-09-15T19:17:32.197+00:00","url":"https://junglewise.ai/threats/cve-2026-58701-google-trusty-out-of-bounds-write-via-race-condition"},{"cve":"CVE-2026-58699","cvss":8.4,"epss":0.001,"slug":"cve-2026-58699-android-vp9-decoder-out-of-bounds-read-in-vp9hwd-output-cc","title":"Android VP9 decoder out-of-bounds read in vp9hwd_output.cc","severity":"high","exploited":false,"published_at":"2026-09-15T19:17:32.097+00:00","url":"https://junglewise.ai/threats/cve-2026-58699-android-vp9-decoder-out-of-bounds-read-in-vp9hwd-output-cc"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":4,"exploited":0,"vulnerabilities":34},{"week":"2026-08-31","critical":4,"exploited":0,"vulnerabilities":7},{"week":"2026-09-07","critical":8,"exploited":0,"vulnerabilities":106},{"week":"2026-09-14","critical":5,"exploited":1,"vulnerabilities":97},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Google Chrome","slug":"chrome","vulnerabilities":2529,"url":"https://junglewise.ai/threats/technologies/chrome"},{"name":"Google Chrome for iOS","slug":"chrome-for-ios","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/chrome-for-ios"},{"name":"Google Chromium V8","slug":"chromium-v8","vulnerabilities":41,"url":"https://junglewise.ai/threats/technologies/chromium-v8"},{"name":"Google Chromium","slug":"chromium","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/chromium"},{"name":"Google TensorFlow","slug":"tensorflow","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/tensorflow"},{"name":"Google Cloud Platform","slug":"google-cloud-platform","vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/google-cloud-platform"},{"name":"Google Android Framework","slug":"android-framework","vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/android-framework"},{"name":"Google Chrome for Android","slug":"chrome-for-android","vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/chrome-for-android"},{"name":"Google ChromeOS","slug":"chromeos","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/chromeos"},{"name":"Google Pixel Bootloader","slug":"pixel-bootloader","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/pixel-bootloader"},{"name":"Google WebView","slug":"webview","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/webview"},{"name":"Google A2ui\\","slug":"a2ui","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/a2ui"}],"technology":{"hub":true,"name":"Google Android","slug":"android","vendor":{"name":"Google","slug":"google","url":"https://junglewise.ai/threats/vendors/google"},"aliases":[],"category":"operating-system","homepage":"https://www.android.com/","repo_url":"https://android.googlesource.com/","description":"An open-source operating system based on the Linux kernel and designed primarily for touchscreen mobile devices such as smartphones and tablets.","url":"https://junglewise.ai/threats/technologies/android"},"most_severe":[{"cve":"CVE-2023-6345","cvss":9.6,"slug":"cve-2023-6345-google-skia-integer-overflow-vulnerability","title":"Google Skia Integer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2023-11-30T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-6345-google-skia-integer-overflow-vulnerability"},{"cve":"CVE-2023-2136","cvss":9.6,"slug":"cve-2023-2136-google-chrome-skia-integer-overflow-vulnerability","title":"Google Chrome Skia Integer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2023-04-21T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-2136-google-chrome-skia-integer-overflow-vulnerability"},{"cve":"CVE-2026-58704","cvss":8.8,"epss":0.0059,"slug":"cve-2026-58704-google-pixel-improper-authorization-in-cellular-modem","title":"In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) esc","severity":"critical","exploited":true,"published_at":"2026-09-15T19:17:32.297+00:00","url":"https://junglewise.ai/threats/cve-2026-58704-google-pixel-improper-authorization-in-cellular-modem"},{"cve":"CVE-2026-3909","cvss":8.8,"epss":0.0039,"slug":"cve-2026-3909-google-skia-out-of-bounds-write-in-google-chrome","title":"Google Skia out-of-bounds write in Google Chrome","severity":"critical","exploited":true,"published_at":"2026-03-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-3909-google-skia-out-of-bounds-write-in-google-chrome"},{"cve":"CVE-2025-48543","cvss":8.8,"epss":0.0031,"slug":"cve-2025-48543-google-android-runtime-use-after-free-in-system-server","title":"Google Android Runtime use-after-free in system_server","severity":"critical","exploited":true,"published_at":"2025-09-04T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-48543-google-android-runtime-use-after-free-in-system-server"},{"cve":"CVE-2025-48572","cvss":7.8,"epss":0.0021,"slug":"cve-2025-48572-google-android-framework-privilege-escalation-via-background","title":"Google Android Framework privilege escalation via background activity launch","severity":"critical","exploited":true,"published_at":"2025-12-02T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-48572-google-android-framework-privilege-escalation-via-background"},{"cve":"CVE-2024-36971","cvss":7.8,"slug":"cve-2024-36971-android-kernel-remote-code-execution-vulnerability","title":"Android Kernel Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2024-08-07T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-36971-android-kernel-remote-code-execution-vulnerability"},{"cve":"CVE-2023-35674","cvss":7.8,"slug":"cve-2023-35674-android-framework-privilege-escalation-vulnerability","title":"Android Framework Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2023-09-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-35674-android-framework-privilege-escalation-vulnerability"},{"cve":"CVE-2023-20963","cvss":7.8,"slug":"cve-2023-20963-android-framework-privilege-escalation-vulnerability","title":"Android Framework Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2023-04-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-20963-android-framework-privilege-escalation-vulnerability"},{"cve":"CVE-2011-1823","cvss":7.8,"slug":"cve-2011-1823-android-os-privilege-escalation-vulnerability","title":"Android OS Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2022-09-08T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2011-1823-android-os-privilege-escalation-vulnerability"}],"generated_at":"2026-09-26T11:07:00.153785+00:00"}