Vulnerabilities in google

6,748 results
Vexday analysis

Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.

CVE-2026-11293CRITICALUse after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.2%CVE-2026-9981MEDIUMInappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive infoEPSS 0.2%CVE-2025-12728MEDIUMInappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user tEPSS 0.2%CVE-2026-11185HIGHUse after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to exEPSS 0.2%CVE-2026-11142MEDIUMInsufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via EPSS 0.2%CVE-2026-11078MEDIUMInappropriate implementation in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendereEPSS 0.2%CVE-2026-11275MEDIUMInappropriate implementation in Page Info in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2026-87567MEDIUMUI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoEPSS 0.2%CVE-2026-11204MEDIUMInappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restricEPSS 0.2%CVE-2018-9375HIGHIn multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confusEPSS 0.2%CVE-2026-11135MEDIUMInsufficient policy enforcement in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary accessEPSS 0.2%CVE-2025-11212MEDIUMInappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to eEPSS 0.2%CVE-2026-10018MEDIUMInteger overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information froEPSS 0.2%CVE-2026-11258MEDIUMInappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user toEPSS 0.2%CVE-2026-11197MEDIUMInsufficient policy enforcement in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendereEPSS 0.2%CVE-2018-9413HIGHIn handle_notification_response of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remEPSS 0.2%CVE-2026-3063HIGHInappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a user to install a maliEPSS 0.2%CVE-2026-95376HIGHExternally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineeriEPSS 0.2%CVE-2026-87568MEDIUMImproper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2026-93380LOWRace condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and EPSS 0.2%