Android's vulnerability disclosure profile spans the mobile operating system itself, its bundled browser and SDK tooling, and related core libraries such as OpenCore and Play Core Library. The recurring weakness classes—information exposure, path traversal, and improper permission preservation—reflect the complexity of inter-process communication, file-system access control, and sensitive-data handling across a highly modular system deployed on billions of devices. The vendor's disclosures concentrate on the operating system and framework layer rather than scattered across a vast application ecosystem, resulting in a comparatively modest CVE volume despite Android's enormous installed base and prominence in the threat landscape. Defenders should prioritize monthly security patch cycles for deployed devices and treat exposure of sensitive information vulnerabilities as particularly relevant to platform-layer security, since such flaws can affect multiple applications simultaneously through shared system services. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Android over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8913HIGH A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create | Aug 12, 2020 | 8.8 | 29 | NO | NO |
CVE-2011-4699MEDIUM The Ubermedia Twidroyd Legacy (com.twidroydlegacy) application 4.3.11 for Android does not properly protect data, which allows remote attackers to read or modify Twitter informatio | Jan 25, 2012 | 6.4 | 20 | NO | NO |
CVE-2011-4698MEDIUM The AndroidAppTools Easy Filter (com.phoneblocker.android) application 1.1 and 1.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS m | Jan 25, 2012 | 6.4 | 20 | NO | NO |
CVE-2008-7298MEDIUM The Android browser in Android cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbi | Aug 9, 2011 | 5.8 | 20 | NO | NO |
CVE-2011-4867MEDIUM The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a pas | Jan 25, 2012 | 5.8 | 19 | NO | NO |
CVE-2011-4866MEDIUM The Kaixin001 (com.kaixin001.activity) application 1.3.1 and 1.3.3 for Android does not properly protect data, which allows remote attackers to read or modify contact information a | Jan 25, 2012 | 6.4 | 19 | NO | NO |
CVE-2011-4769MEDIUM The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages a | Jan 25, 2012 | 5.8 | 19 | NO | NO |
CVE-2011-4705MEDIUM The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attackers to read or modify blacklists | Jan 25, 2012 | 5.8 | 19 | NO | NO |
CVE-2011-4704MEDIUM The Voxofon (com.voxofon) application before 2.5.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS information via a crafted applica | Jan 25, 2012 | 5.8 | 19 | NO | NO |
CVE-2011-4700MEDIUM The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information | Jan 25, 2012 | 5.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Android.
Media articles that mention a CVE ID that affects a product developed by Android — matched by CVE ID, not by vendor name.