Vulnerabilities in google

7,001 results
Vexday analysis

Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.

CVE-2026-28587CRITICALIn MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This EPSS 0.2%CVE-2026-49883CRITICALIn checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permissioEPSS 0.2%CVE-2026-17724MEDIUMRace in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) vEPSS 0.2%CVE-2026-12014HIGHUse after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a saEPSS 0.2%CVE-2026-103627MEDIUMInformation leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTMLEPSS 0.2%CVE-2026-10011LOWInappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2025-13640LOWInappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass authentication via physEPSS 0.2%CVE-2026-17666CRITICALCryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discEPSS 0.2%CVE-2026-10001HIGHUse after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2026-11186MEDIUMInappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UEPSS 0.2%CVE-2026-11122MEDIUMInappropriate implementation in Keyboard in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTEPSS 0.2%CVE-2025-36895HIGHInformation disclosureEPSS 0.2%CVE-2026-7943MEDIUMInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised thEPSS 0.2%CVE-2026-8554LOWType Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer proceEPSS 0.2%CVE-2026-11189MEDIUMInsufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to iEPSS 0.2%CVE-2024-34740HIGHIn attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection due to an integer oveEPSS 0.2%CVE-2026-11222MEDIUMIncorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafteEPSS 0.2%CVE-2024-31319HIGHIn updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a possible cross-user data leak due to a conEPSS 0.2%CVE-2026-8022LOWInappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in spEPSS 0.2%CVE-2019-13762—Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded EPSS 0.2%