Vulnerabilities in Google
7,003 resultsCVE-2026-0133HIGHIn smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permissiEPSS 0.1%CVE-2026-0125HIGHIn multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of priEPSS 0.1%CVE-2026-0158MEDIUMIn Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disEPSS 0.1%CVE-2025-22442HIGHIn multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications into a newly created EPSS 0.1%CVE-2026-0150HIGHIn ExecuteGraph command handler of EdgeTPU firmware, there is a possible out of bounds write due to an integer overflow. This could lead to EPSS 0.1%CVE-2023-21399—there is a possible way to bypass cryptographic assurances due to a logic error in the code. This could lead to local escalation of privilegEPSS 0.1%CVE-2026-11290MEDIUMInteger overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a mEPSS 0.1%CVE-2026-58841HIGHIn multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This couldEPSS 0.1%CVE-2024-29779HIGHthere is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additionaEPSS 0.1%CVE-2025-48625HIGHIn multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB data when the screen is off due to a raceEPSS 0.1%CVE-2026-0112HIGHIn vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilegEPSS 0.1%CVE-2026-0054LOWIn isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a missing permission cheEPSS 0.1%CVE-2026-0057LOWIn Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission EPSS 0.1%CVE-2026-58856LOWIn returnOutputBufferLocked of DeprecatedCamera3StreamSplitter.cpp, there is a possible out-of-bounds read due to a missing bounds check. ThEPSS 0.1%CVE-2026-58834MEDIUMIn setPermissionGrantState of DevicePolicyManagerService.java, there is a possible persistent denial of service due to improper input validaEPSS 0.1%CVE-2026-0121LOWIn VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional EPSS 0.1%CVE-2025-36916HIGHIn PrepareWorkloadBuffers of gxp_main_actor.cc, there is a possible double fetch due to a race condition. This could lead to local escalatioEPSS 0.1%CVE-2026-106405MEDIUMRace condition in CustomTabs in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass web origin policy via EPSS 0.1%CVE-2026-0094HIGHIn getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to mislEPSS 0.1%CVE-2026-56906HIGHIn ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege withEPSS 0.1%