Vulnerabilities in google
7,001 resultsVexday analysis
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2026-10012HIGHUse after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentEPSS 0.2%CVE-2026-11264MEDIUMPolicy bypass in Content Security Policy in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policyEPSS 0.2%CVE-2026-9998HIGHInteger overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to poteEPSS 0.2%CVE-2026-11034MEDIUMInsufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker toEPSS 0.2%CVE-2026-13822MEDIUMInappropriate implementation in Extensions in Google Chrome on Android prior to 150.0.7871.47 allowed an attacker who convinced a user to inEPSS 0.2%CVE-2026-12459MEDIUMInappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbitrary scripts or HTMEPSS 0.2%CVE-2026-11236HIGHInsufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rEPSS 0.2%CVE-2018-9440MEDIUMIn parse of M3UParser.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service witEPSS 0.2%CVE-2026-79222MEDIUMIncorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin poEPSS 0.2%CVE-2026-11628MEDIUMUse after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap corruption via physicaEPSS 0.2%CVE-2026-0165MEDIUMIn several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to reEPSS 0.2%CVE-2026-12453MEDIUMInsufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised tEPSS 0.2%CVE-2026-14133MEDIUMRace in History Embeddings in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page.EPSS 0.2%CVE-2025-12434MEDIUMRace in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gEPSS 0.2%CVE-2026-87551MEDIUMImproper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bEPSS 0.2%CVE-2026-12034HIGHInsufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacEPSS 0.2%CVE-2026-10002HIGHUse after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a craEPSS 0.2%CVE-2023-21272—In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation EPSS 0.2%CVE-2026-11302MEDIUMInsufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass discretEPSS 0.2%CVE-2026-11700HIGHUse after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potEPSS 0.2%