CVE-2014-0900: Google Android

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and consequently bypass MDM restrictions by leveraging failure to update the mAdminMap data structure.

Affected products

  • Google Android: up to and including 4.4.1

Published 2018-04-20. Last modified 2026-06-17.