Vulnerabilities in Google

7,001 results
CVE-2025-12910MEDIUMInappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain potentially sensitive inEPSS 0.1%CVE-2018-9383MEDIUMIn asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local informEPSS 0.1%CVE-2023-21390HIGHIn Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of pEPSS 0.1%CVE-2023-21330—In Overlay Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informaEPSS 0.1%CVE-2025-48579HIGHIn multiple functions of MediaProvider.java, there is a possible external storage write permission bypass due to a confused deputy. This couEPSS 0.1%CVE-2023-48406—there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic error in the code. This could lead to locaEPSS 0.1%CVE-2023-21335—In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information diEPSS 0.1%CVE-2024-0022MEDIUMIn multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationActivity of another usEPSS 0.1%CVE-2023-35679—In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead to local informationEPSS 0.1%CVE-2024-25992HIGHIn tmu_tz_control of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of priEPSS 0.1%CVE-2023-48412—In private_handle_t of mali_gralloc_buffer.h, there is a possible information leak due to a logic error in the code. This could lead to locEPSS 0.1%CVE-2024-0017MEDIUMIn shouldUseNoOpLocation of CameraActivity.java, there is a possible confused deputy due to a permissions bypass. This could lead to local iEPSS 0.1%CVE-2024-23706HIGHIn multiple locations, there is a possible bypass of health data permissions due to an improper input validation. This could lead to local eEPSS 0.1%CVE-2023-21388—In Settings, there is a possible restriction bypass due to a missing permission check. This could lead to local escalation of privilege withEPSS 0.1%CVE-2023-21336—In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informatioEPSS 0.1%CVE-2025-12474LOWlibjxl: Uninitialized memory read in decoder due to incorrect optimization in patch handlingEPSS 0.1%CVE-2024-32892HIGHIn handle_init of goodix/main/main.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of prEPSS 0.1%CVE-2023-35682HIGHIn hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary components due to a confused deputy. ThEPSS 0.1%CVE-2026-0035HIGHIn createRequest of MediaProvider.java, there is a possible way for an app to gain read/write access to non-existing files due to a logic erEPSS 0.1%CVE-2023-20971HIGHIn removePermission of PermissionManagerServiceImpl.java, there is a possible way to obtain dangerous permissions without user consent due tEPSS 0.1%