Skip to content
COOEY

FAIL › dossier

android

PRODUCT

· dossier confidence 50%

PROFILE
CategorysoftwareWhat they doAndroid is an operating system developed by Google for mobile devices such as smartphones and tablets.
SECURITY POSTURE

The company has faced multiple high and critical security vulnerabilities, indicating a potential lack of robust security practices.

Notable failures
  • CVE-2025-48572 (high [RCE])
  • CVE-2025-48633 (high)
  • CVE-2025-48543 (high [RCE])
  • CVE-2025-48595 (high [RCE], local privilege escalation and code execution)
  • CVE-2024-36971 (high [RCE])
  • CVE-2024-43093 (high)
  • CVE-2024-32896 (high)
  • CVE-2024-29748 (high)
  • CVE-2024-29745 (high)
  • CVE-2024-32896 (high)
  • CVE-2023-35674 (high)
  • CVE-2023-20963 (high)
  • CVE-2022-0923 (high)
  • CVE-2022-0523 (high)
  • CVE-2021-0920 (high)
  • CVE-2021-1048 (high)
  • CVE-2021-2215 (high)
  • CVE-2020-0041 (high)
  • CVE-2026-14106 (critical)
  • CVE-2026-11029 (critical)
Patterns: Repeated unpatched high-severity vulnerabilities; Privilege escalation vulnerabilities; Use-after-free vulnerabilities; Insufficient input validation leading to code execution
Reputationsevere-fallout (-0.11) · 7 trusted sources CoverageCISA · NVD · app.opencve.io · cooey · cooey · sec.cloudapps.cisco.com
FAILURE HISTORY · 21
DATEEVENTSEVSUMMARY
2024-08-07 CVE-2024-36971 high Android kernel RCE vulnerability actively exploited in the wild.
2022-05-23 CVE-2021-1048 high Android kernel use-after-free vulnerability allows privilege escalation and is actively exploited in the wild.
2021-11-03 CVE-2020-0041 high An out-of-bounds write vulnerability in the Android kernel allowed local privilege escalation when chained with other known CVEs.
2021-11-03 CVE-2019-2215 high A use-after-free vulnerability in the Android kernel allowed privilege escalation from an app to the Linux kernel, often chained with other CVEs to gain full control.
2022-05-23 CVE-2021-0920 high Android kernel race condition allows privilege escalation via use-after-free.
2025-12-02 CVE-2025-48572 high Android Framework Privilege Escalation Vulnerability actively exploited
2025-12-02 CVE-2025-48633 high Android Framework exposed info disclosure flaw
2025-09-04 CVE-2025-48543 high Android Runtime Use-After-Free Vulnerability exploited
2023-09-13 CVE-2023-35674 high An Android Framework vulnerability allows privilege escalation, actively exploited in the wild, impacting DIB organizations using Android-powered devices or systems.
2023-04-13 CVE-2023-20963 high Android Framework Privilege Escalation Vulnerability
2022-09-08 CVE-2011-1823 high Android OS kernel vold daemon allowed remote code execution via a Netlink socket, leading to root privileges
2026-06-02 CVE-2025-48595 high Android Framework integer overflow vulnerability enables local privilege escalation and code execution.
2024-11-07 CVE-2024-43093 high Android Framework contains a privilege escalation vulnerability actively exploited in the wild.
2024-06-13 CVE-2024-32896 high Android Pixel firmware contains a privilege escalation vulnerability actively exploited in the wild.
2024-04-04 CVE-2024-29745 high Android Pixel fastboot firmware leaks sensitive data during device unlocking and flashing, enabling unauthorized access to device secrets.
2024-04-04 CVE-2024-29748 high Android Pixel devices allow attackers to bypass factory reset via a privilege escalation vulnerability.
2024-03-05 CVE-2023-21237 high Android Pixel devices are vulnerable to information disclosure via misleading UI that hides foreground service notifications.
2026-06-30 CVE-2026-14106 critical Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
2026-06-09 CVE-2026-34691 critical CVE-2026-34691: Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are af
2026-06-04 CVE-2026-11029 critical CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop in Google Chrome on
2016-04-07 CVE-2016-1019 critical CVE-2016-1019: Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a den
SENTIMENT · TRUSTED SOURCES
synthesisneutral+0.00
No sentiment expressed; purely factual NVD entry.
synthesissevere-fallout-0.60
Android's kernel privilege escalation flaw was widely recognized as critical, especially when chained with other exploits, though vendor response details are absent from the provided sources.
CISA ↗severe-fallout+0.00
No direct mention of CVE-2019-2215; source is generic CISA homepage.
www.cvefind.com ↗severe-fallout+0.00
Generic CVE database page; no specific sentiment toward Android.
app.opencve.io ↗severe-fallout+0.00
Generic CVE database page; no specific sentiment toward Android.
sec.cloudapps.cisco.com ↗severe-fallout+0.00
Cisco advisory unrelated to Android; no sentiment toward Android.
NVD ↗severe-fallout+0.00
NVD page unrelated to Android; no sentiment toward Android.
cooey ↗neutral+0.00
No sentiment expressed; purely factual NVD entry.
"Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation."
cooey ↗severe-fallout-0.80
Critical kernel flaw allowing privilege escalation, observed in exploit chains, indicating severe impact.
"Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain 'AbstractEmu.'"
Open questions: Why have there been so many high-severity vulnerabilities in Android? · What improvements has Android Inc. made to its security practices? · How does Android Inc. plan to address these recurring vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-26 03:42:55.129228+00:00