Vulnerabilities in google
6,721 resultsVexday analysis
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2026-2322MEDIUMInappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage EPSS 0.2%CVE-2026-11098MEDIUMInsufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the EPSS 0.2%CVE-2026-91719MEDIUMCode injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page.EPSS 0.2%CVE-2026-13939LOWInsufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had EPSS 0.2%CVE-2026-95285HIGHMissing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renEPSS 0.2%CVE-2026-91744MEDIUMRace condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the reEPSS 0.2%CVE-2024-3175HIGHInsufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalationEPSS 0.2%CVE-2026-11633HIGHUse after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a maliciEPSS 0.2%CVE-2026-14114HIGHInappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoEPSS 0.2%CVE-2026-11159MEDIUMUninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML pagEPSS 0.2%CVE-2026-2323MEDIUMInappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a craEPSS 0.2%CVE-2026-14105CRITICALInsufficient policy enforcement in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy viaEPSS 0.2%CVE-2026-0154HIGHIn Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption. This could lead to remote coEPSS 0.2%CVE-2026-0161HIGHIn numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote escEPSS 0.2%CVE-2026-10916MEDIUMInsufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromisedEPSS 0.2%CVE-2026-79186LOWIncorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer procesEPSS 0.2%CVE-2024-47023HIGHthere is a possible man-in-the-middle attack due to a logic error in the code. This could lead to remote escalation of privilege with no addEPSS 0.2%CVE-2026-95308LOWInteger overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to poEPSS 0.2%CVE-2024-10604MEDIUMIdentifiable Header Values In Fuchsia Leading To Tracking of The UserEPSS 0.2%CVE-2026-79002LOWIncorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer EPSS 0.2%