Vulnerabilities in google
6,568 resultsVexday analysis
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2025-5065MEDIUMInappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofinEPSS 0.4%CVE-2026-15767HIGHHeap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code insidEPSS 0.4%CVE-2023-35662—there is a possible out of bounds write due to buffer overflow. This could lead to remote code execution with no additional execution privilEPSS 0.4%CVE-2026-79064CRITICALUse after free in Network in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execuEPSS 0.4%CVE-2026-79026CRITICALUse after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially EPSS 0.4%CVE-2024-6996LOWRace in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to pEPSS 0.4%CVE-2026-87526CRITICALUse after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially eEPSS 0.4%CVE-2026-87504CRITICALUse after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary EPSS 0.4%CVE-2023-35646—In TBD of TBD, there is a possible stack buffer overflow due to a missing bounds check. This could lead to remote code execution with no addEPSS 0.4%CVE-2026-12447HIGHHeap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code inside a sandboxEPSS 0.4%CVE-2022-2619—Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to iEPSS 0.4%CVE-2026-87609CRITICALUse after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the EPSS 0.4%CVE-2026-79129CRITICALUse after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to EPSS 0.4%CVE-2026-12466HIGHHeap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via aEPSS 0.4%CVE-2024-11115HIGHInsufficient policy enforcement in Navigation in Google Chrome on iOS prior to 131.0.6778.69 allowed a remote attacker to perform privilege EPSS 0.4%CVE-2026-10910HIGHType Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafEPSS 0.4%CVE-2025-11756HIGHUse after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process EPSS 0.4%CVE-2026-8558HIGHOut of bounds write in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox vEPSS 0.4%CVE-2026-9973HIGHOut of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via EPSS 0.4%CVE-2024-12695HIGHOut of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via EPSS 0.4%