Vulnerabilities in google

6,710 results
Vexday analysis

Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.

CVE-2026-11074HIGHUse after free in WebRTC in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted EPSS 0.4%CVE-2026-4439HIGHOut of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a EPSS 0.4%CVE-2026-3540HIGHInappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory EPSS 0.4%CVE-2026-11068HIGHUse after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox viEPSS 0.4%CVE-2026-11147HIGHUse after free in WebML in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandEPSS 0.4%CVE-2026-9114HIGHUse after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via EPSS 0.4%CVE-2026-14108HIGHUse after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.4%CVE-2026-13035HIGHUse after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a maliciEPSS 0.4%CVE-2026-10995HIGHHeap buffer overflow in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specifiEPSS 0.4%CVE-2026-11024HIGHStack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit stack corruption via EPSS 0.4%CVE-2018-6171—Use after free in Bluetooth in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extensionEPSS 0.4%CVE-2026-6363HIGHType Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access vEPSS 0.4%CVE-2026-0900HIGHInappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruptioEPSS 0.4%CVE-2026-10923HIGHUse after free in WebAppInstalls in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via aEPSS 0.4%CVE-2026-10938HIGHInappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer proEPSS 0.4%CVE-2026-55306HIGHIn Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote denial of service with EPSS 0.4%CVE-2024-0810MEDIUMInsufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a maEPSS 0.4%CVE-2026-75062CRITICALEval Injection in google/langfun via default lf.query protocolEPSS 0.4%CVE-2024-7024CRITICALInappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escapeEPSS 0.3%CVE-2026-13776CRITICALType Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentiEPSS 0.3%