Vulnerabilities in Google

7,001 results
CVE-2025-48598MEDIUMIn multiple locations, there is a possible way to alter the primary user's face unlock settings due to a confused deputy. This could lead toEPSS 0.1%CVE-2023-40130HIGHIn notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. This could lead to locEPSS 0.1%CVE-2023-21396—In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation ofEPSS 0.1%CVE-2024-43085HIGHIn handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due toEPSS 0.1%CVE-2024-31310HIGHIn newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill EPSS 0.1%CVE-2025-48582HIGHIn multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an intent redirect. ThiEPSS 0.1%CVE-2026-11241HIGHInsufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment EPSS 0.1%CVE-2023-35675—In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files played by another user oEPSS 0.1%CVE-2026-93376MEDIUMOut of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read meEPSS 0.1%CVE-2024-31316HIGHIn onResult of AccountManagerService.java, there is a possible way to perform an arbitrary background activity launch due to parcel mismatchEPSS 0.1%CVE-2024-34729HIGHIn multiple locations, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation ofEPSS 0.1%CVE-2024-43087HIGHIn getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in tEPSS 0.1%CVE-2025-22441HIGHIn getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible way to load arbitrary java code in a privileEPSS 0.1%CVE-2026-58941HIGHIn multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local esEPSS 0.1%CVE-2024-0042MEDIUMIn TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DEPSS 0.1%CVE-2023-0460MEDIUMRemote code execution in YouTube Android Player API SDKEPSS 0.1%CVE-2024-0024HIGHIn multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input vaEPSS 0.1%CVE-2024-34726HIGHIn PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local esEPSS 0.1%CVE-2025-26427MEDIUMIn multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privileEPSS 0.1%CVE-2025-48622MEDIUMIn ProcessArea of dng_misc_opcodes.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local informatioEPSS 0.1%