Bluestacks develops a widely used Android emulation platform that allows users to run mobile applications on personal computers, creating a bridge between mobile and desktop environments. The vendor's vulnerability footprint centers on its core emulation products and recurs through weakness classes including improper certificate validation, input-validation flaws, privilege-management issues, and permission-assignment errors—characteristic of software that must manage sandboxing boundaries, network trust decisions, and host-system integration. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bluestacks over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0701HIGH BlueStacks App Player (BlueStacks App Player for Windows 3.0.0 to 4.31.55, BlueStacks App Player for macOS 2.0.0 and later) allows an attacker on the same network segment to bypass | Nov 15, 2018 | 8.8 | 27 | NO | NO |
CVE-2019-12936HIGH BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions. | Jun 23, 2019 | 8.0 | 26 | NO | NO |
CVE-2016-4288HIGH A local privilege escalation vulnerability exists in BlueStacks App Player. The BlueStacks App Player installer creates a registry key with weak permissions that allows users to ex | Jan 6, 2017 | 8.4 | 26 | NO | NO |
CVE-2020-24367HIGH Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later executed by a higher-privileged | Nov 10, 2020 | 7.8 | 23 | NO | NO |
CVE-2019-14220MEDIUM An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a virtual machine (VM) to enable Android app | Sep 24, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-25548MEDIUM BlueStacks 4.80.0.1060 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input to the search field. Attackers | Mar 21, 2026 | 6.2 | 21 | NO | NO |
A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obtain sensitive information. | Aug 5, 2025 | 3.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bluestacks.
Media articles that mention a CVE ID that affects a product developed by Bluestacks — matched by CVE ID, not by vendor name.