Vulnerabilities in Google
6,567 resultsVexday analysis
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2021-37964—Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606.54 allowed an attacker with a rogue wireEPSS 0.5%CVE-2025-48530HIGHIn multiple locations, there is a possible condition that results in OOB accesses due to an incorrect bounds check. This could lead to remotEPSS 0.5%CVE-2025-7657HIGHUse after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a craEPSS 0.5%CVE-2023-1213HIGHUse after free in Swiftshader in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to potentially exploit heap corruption via aEPSS 0.5%CVE-2023-2458HIGHUse after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who convinced a user to engEPSS 0.5%CVE-2024-7003MEDIUMInappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in spEPSS 0.5%CVE-2024-5835MEDIUMHeap buffer overflow in Tab Groups in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in speciEPSS 0.5%CVE-2023-0697—Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the cEPSS 0.5%CVE-2022-42541CRITICALRemote code executionEPSS 0.5%CVE-2021-21138—Use after free in DevTools in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform a sandbox escape via a craEPSS 0.5%CVE-2024-10229HIGHInappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass site isolation via a EPSS 0.5%CVE-2024-8904HIGHType Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted EPSS 0.5%CVE-2024-7969HIGHType Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a craftedEPSS 0.5%CVE-2023-21287—In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code execution with no additionalEPSS 0.5%CVE-2026-87527CRITICALBuffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox viaEPSS 0.5%CVE-2024-9121HIGHInappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds meEPSS 0.5%CVE-2026-78948CRITICALBuffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox viaEPSS 0.5%CVE-2026-87654CRITICALBuffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside tEPSS 0.5%CVE-2026-76036CRITICALBuffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside tEPSS 0.5%CVE-2026-79130CRITICALBuffer overflow in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox viaEPSS 0.5%