cd ../exploit-db
root@mhfh:~#ls -la /var/db/exploits/android/
android_exploit_db.json
🤖 Android Exploit DB
Curated Android vulnerabilities across AOSP, Pixel, and Samsung, sandbox escapes, kernel LPEs, infoleaks. Each entry links to a full technical writeup with PoC and downloads.
11
total
3
crit
7
high
1
med
android-exploit-db.sh --query
$ severity:
$ type:
$ sort:
CVE-2026-0059High
Android System remote code execution
type: RCEaffected: 14, 15, 16, 16 QPR2date: 2026-06-01status: Vendor confirmed
$ cat /var/db/exploits/CVE-2026-0059.json →
CVE-2026-0073Critical
adbd wireless debugging remote shell
type: RCEaffected: 14-16date: 2026-05-05status: Publicly disclosed
$ cat /var/db/exploits/CVE-2026-0073.json →
CVE-2026-0032High
mem_protect.c out-of-bounds write
type: LPEaffected: Kernel 14-15date: 2026-03-02status: Publicly disclosed
$ cat /var/db/exploits/CVE-2026-0032.json →
CVE-2026-0114Critical
Pixel modem remote code execution
type: RCEaffected: Supported Google Pixel devicesdate: 2026-03-01status: Vendor confirmed
$ cat /var/db/exploits/CVE-2026-0114.json →
CVE-2026-0006Critical
Android System remote code execution
type: RCEaffected: Android 16date: 2026-03-01status: Vendor confirmed
$ cat /var/db/exploits/CVE-2026-0006.json →
CVE-2026-21385High
Graphics component buffer over-read
type: InfoLeakaffected: Qualcomm chipsetsdate: 2026-03-01status: Publicly disclosed
$ cat /var/db/exploits/CVE-2026-21385.json →
CVE-2025-48543High
Chrome sandbox escape use-after-free
type: Sandboxaffected: System 14-16date: 2025-11-20status: Publicly disclosed
$ cat /var/db/exploits/CVE-2025-48543.json →
CVE-2024-43093High
Framework path traversal sandbox escape
type: Sandboxaffected: 12-15date: 2024-11-04status: Publicly disclosed
$ cat /var/db/exploits/CVE-2024-43093.json →
CVE-2024-32896High
Pixel firmware privilege escalation
type: LPEaffected: Pixel ≤14date: 2024-06-11status: Publicly disclosed
$ cat /var/db/exploits/CVE-2024-32896.json →
CVE-2023-21492Medium
Samsung kernel pointer leak
type: InfoLeakaffected: Samsung ≤13date: 2023-05-09status: Publicly disclosed
$ cat /var/db/exploits/CVE-2023-21492.json →
CVE-2023-20963High
WorkSource parcel mismatch (in-the-wild)
type: LPEaffected: ≤13date: 2023-03-13status: Publicly disclosed
$ cat /var/db/exploits/CVE-2023-20963.json →
11 of 11 record(s)