Vulnerabilities in google

6,721 results
Vexday analysis

Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.

CVE-2026-95309MEDIUMUI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafteEPSS 0.3%CVE-2026-7998MEDIUMInsufficient validation of untrusted input in Dialog in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised tEPSS 0.3%CVE-2026-11100CRITICALUse after free in File Input in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specEPSS 0.3%CVE-2026-14082MEDIUMRace in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (ChromiEPSS 0.3%CVE-2026-93383MEDIUMInformation leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTEPSS 0.3%CVE-2026-14015MEDIUMRace in WebRTC in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML pagEPSS 0.3%CVE-2026-93387MEDIUMImproper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafteEPSS 0.3%CVE-2026-103631—Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox viaEPSS 0.3%CVE-2026-95359LOWUninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderEPSS 0.3%CVE-2026-12019HIGHHeap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised EPSS 0.3%CVE-2025-13639HIGHInappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write viaEPSS 0.3%CVE-2018-9470HIGHIn bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote eEPSS 0.3%CVE-2026-0040MEDIUMIn multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead toEPSS 0.3%CVE-2026-0052MEDIUMIn multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead toEPSS 0.3%CVE-2026-4452HIGHInteger overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruptiEPSS 0.3%CVE-2026-0127MEDIUMIn NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This coEPSS 0.3%CVE-2026-14541HIGHAuthentication Bypass and Audience Confusion in MCP Toolbox OAuth ProviderEPSS 0.3%CVE-2026-0039MEDIUMIn multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This couldEPSS 0.3%CVE-2026-87577MEDIUMIncorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a priEPSS 0.3%CVE-2026-13862MEDIUMInsufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on iOS prior to 150.0.7871.47 allowed an aEPSS 0.3%