Vulnerabilities in google
7,001 resultsVexday analysis
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2026-11134MEDIUMInappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafEPSS 0.2%CVE-2026-11220MEDIUMInsufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromisEPSS 0.2%CVE-2026-11192MEDIUMInsufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform EPSS 0.2%CVE-2026-11083MEDIUMInappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin dataEPSS 0.2%CVE-2026-11223MEDIUMInsufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised EPSS 0.2%CVE-2026-15829HIGHSQL Injection and Security Boundary Bypass in googleapis/mcp-toolboxEPSS 0.2%CVE-2023-21238—In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local informEPSS 0.2%CVE-2024-3173HIGHInsufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escaEPSS 0.2%CVE-2026-11296HIGHInappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendeEPSS 0.2%CVE-2026-28573CRITICALIn AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial EPSS 0.2%CVE-2025-48600MEDIUMIn multiple files, there is a possible way to reveal information across users due to a missing permission check. This could lead to local inEPSS 0.2%CVE-2026-11143MEDIUMOut of bounds read in Extensions in Google Chrome on Linux prior to 149.0.7827.53 allowed an attacker who convinced a user to install a maliEPSS 0.2%CVE-2025-48535HIGHIn assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a lauEPSS 0.2%CVE-2026-11252MEDIUMInsufficient policy enforcement in Content Settings in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionarEPSS 0.2%CVE-2026-11274MEDIUMInappropriate implementation in DOM Distiller in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation EPSS 0.2%CVE-2023-21246—In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exceptioEPSS 0.2%CVE-2025-22412HIGHIn multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proxEPSS 0.2%CVE-2026-5899MEDIUMInsufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a userEPSS 0.2%CVE-2026-9123HIGHHeap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute EPSS 0.2%CVE-2026-10942HIGHInappropriate implementation in UI in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform privilege escalatiEPSS 0.2%