Android known exploited vulnerabilities
CISA lists 17 Android CVEs as exploited in the wild. 3 were added in the last 12 months (latest 2026-06-02), and 0 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2019-2215 (Android Kernel): EPSS 72.1%, added 2021-11-03
- CVE-2011-1823 (Android OS): EPSS 41.4%, added 2022-09-08
- CVE-2020-0041 (Android Kernel): EPSS 3.1%, added 2021-11-03
- CVE-2024-32896 (Pixel): EPSS 3.0%, added 2024-06-13
- CVE-2024-36971 (Kernel): EPSS 2.7%, added 2024-08-07
Most affected Android products
Framework (6), Pixel (4), Kernel (3), Android Kernel (2), Runtime (1), Android OS (1).
All Android CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2025-48595 | Framework | Framework Integer Overflow | 2026-06-02 | 2026-06-05 | 1.7% | – |
| CVE-2025-48633 | Framework | Framework Information Disclosure | 2025-12-02 | 2025-12-23 | 0.3% | – |
| CVE-2025-48572 | Framework | Framework Privilege Escalation | 2025-12-02 | 2025-12-23 | 0.3% | – |
| CVE-2025-48543 | Runtime | Runtime Use-After-Free | 2025-09-04 | 2025-09-25 | 0.5% | – |
| CVE-2024-43093 | Framework | Framework Privilege Escalation | 2024-11-07 | 2024-11-28 | 0.7% | – |
| CVE-2024-36971 | Kernel | Kernel Remote Code Execution | 2024-08-07 | 2024-08-28 | 2.7% | – |
| CVE-2024-32896 | Pixel | Pixel Privilege Escalation | 2024-06-13 | 2024-07-04 | 3.0% | – |
| CVE-2024-29748 | Pixel | Pixel Privilege Escalation | 2024-04-04 | 2024-04-25 | 0.7% | – |
| CVE-2024-29745 | Pixel | Pixel Information Disclosure | 2024-04-04 | 2024-04-25 | 0.5% | – |
| CVE-2023-21237 | Pixel | Pixel Information Disclosure | 2024-03-05 | 2024-03-26 | 0.3% | – |
| CVE-2023-35674 | Framework | Framework Privilege Escalation | 2023-09-13 | 2023-10-04 | 2.6% | – |
| CVE-2023-20963 | Framework | Framework Privilege Escalation | 2023-04-13 | 2023-05-04 | 1.5% | – |
| CVE-2011-1823 | Android OS | OS Privilege Escalation | 2022-09-08 | 2022-09-29 | 41.4% | – |
| CVE-2021-1048 | Kernel | Kernel Use-After-Free | 2022-05-23 | 2022-06-13 | 1.0% | – |
| CVE-2021-0920 | Kernel | Kernel Race Condition | 2022-05-23 | 2022-06-13 | 0.8% | – |
| CVE-2020-0041 | Android Kernel | Kernel Out-of-Bounds Write | 2021-11-03 | 2022-05-03 | 3.1% | – |
| CVE-2019-2215 | Android Kernel | Kernel Use-After-Free | 2021-11-03 | 2022-05-03 | 72.1% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors