Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Android

First CVE: Feb 11, 2009Active for: 17 yearsTotal CVEs: 20
11.6
VTI Score
Low

Android's vulnerability disclosure profile spans the mobile operating system itself, its bundled browser and SDK tooling, and related core libraries such as OpenCore and Play Core Library. The recurring weakness classes—information exposure, path traversal, and improper permission preservation—reflect the complexity of inter-process communication, file-system access control, and sensitive-data handling across a highly modular system deployed on billions of devices. The vendor's disclosures concentrate on the operating system and framework layer rather than scattered across a vast application ecosystem, resulting in a comparatively modest CVE volume despite Android's enormous installed base and prominence in the threat landscape. Defenders should prioritize monthly security patch cycles for deployed devices and treat exposure of sensitive information vulnerabilities as particularly relevant to platform-layer security, since such flaws can affect multiple applications simultaneously through shared system services. Current severity, exploitation, and exposure details are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Android over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2009
17 years ago
Most Recent CVE
Aug 12, 2020
2,172 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-8913HIGH
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create
Aug 12, 20208.829NONO
CVE-2011-4699MEDIUM
The Ubermedia Twidroyd Legacy (com.twidroydlegacy) application 4.3.11 for Android does not properly protect data, which allows remote attackers to read or modify Twitter informatio
Jan 25, 20126.420NONO
CVE-2011-4698MEDIUM
The AndroidAppTools Easy Filter (com.phoneblocker.android) application 1.1 and 1.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS m
Jan 25, 20126.420NONO
CVE-2008-7298MEDIUM
The Android browser in Android cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbi
Aug 9, 20115.820NONO
CVE-2011-4867MEDIUM
The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a pas
Jan 25, 20125.819NONO
CVE-2011-4866MEDIUM
The Kaixin001 (com.kaixin001.activity) application 1.3.1 and 1.3.3 for Android does not properly protect data, which allows remote attackers to read or modify contact information a
Jan 25, 20126.419NONO
CVE-2011-4769MEDIUM
The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages a
Jan 25, 20125.819NONO
CVE-2011-4705MEDIUM
The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attackers to read or modify blacklists
Jan 25, 20125.819NONO
CVE-2011-4704MEDIUM
The Voxofon (com.voxofon) application before 2.5.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS information via a crafted applica
Jan 25, 20125.819NONO
CVE-2011-4700MEDIUM
The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information
Jan 25, 20125.819NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
90%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (5.0%)
Unknown19 (95.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (5.0%)
High0 (0.0%)
Unknown19 (95.0%)
User Interaction
None0 (0.0%)
Unknown19 (95.0%)
Required1 (5.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (5.0%)
Unknown19 (95.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Android.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Android — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Android's Products

View all 2 CNAs →

Top CWEs