Vulnerabilities in google
6,721 resultsVexday analysis
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2026-79208MEDIUMMissing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via crafted nEPSS 0.3%CVE-2026-95366MEDIUMUse of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process EPSS 0.3%CVE-2026-0149HIGHIn RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution withEPSS 0.3%CVE-2026-0132HIGHIn Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additionalEPSS 0.3%CVE-2024-40673MEDIUMIn Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to impEPSS 0.3%CVE-2026-10969HIGHInsufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromisEPSS 0.3%CVE-2026-10970HIGHInsufficient validation of untrusted input in InterestGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had comprEPSS 0.3%CVE-2026-11027MEDIUMInsufficient validation of untrusted input in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised theEPSS 0.3%CVE-2026-79276MEDIUMImproper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering EPSS 0.3%CVE-2026-14052MEDIUMInsufficient policy enforcement in FileSystem in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass discretionary acceEPSS 0.3%CVE-2026-10981MEDIUMInsufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised tEPSS 0.3%CVE-2026-79074MEDIUMInformation leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obEPSS 0.3%CVE-2026-7357HIGHUse after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentiEPSS 0.3%CVE-2026-8513HIGHUse after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer proceEPSS 0.3%CVE-2025-1916HIGHUse after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extensionEPSS 0.3%CVE-2026-79287MEDIUMObservable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafEPSS 0.3%CVE-2026-9881CRITICALUse after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious EPSS 0.3%CVE-2026-9990HIGHUse after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage inEPSS 0.3%CVE-2026-79220MEDIUMInformation leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obEPSS 0.3%CVE-2026-7350HIGHUse after free in WebMIDI in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potEPSS 0.3%