Vulnerabilities in google
7,001 resultsVexday analysis
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2026-13945LOWInsufficient policy enforcement in Extensions in Google Chrome on Linux prior to 150.0.7871.47 allowed an attacker who convinced a user to iEPSS 0.2%CVE-2024-32900CRITICALIn lwis_fence_signal of lwis_debug.c, there is a possible Use after Free due to improper locking. This could lead to local escalation of priEPSS 0.2%CVE-2026-13948LOWInsufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a EPSS 0.2%CVE-2026-95298HIGHUse after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside theEPSS 0.2%CVE-2025-12436MEDIUMPolicy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extensioEPSS 0.2%CVE-2026-12022HIGHRace in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to EPSS 0.2%CVE-2026-11190MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malEPSS 0.2%CVE-2023-21361—In Bluetooth, there is a possibility of code-execution due to a use after free. This could lead to paired device escalation of privilege in EPSS 0.2%CVE-2026-11036MEDIUMInappropriate implementation in DOM in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a craEPSS 0.2%CVE-2026-0082CRITICALIn tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure defaultEPSS 0.2%CVE-2026-11081MEDIUMInappropriate implementation in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a EPSS 0.2%CVE-2026-11684LOWInsufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the utilitEPSS 0.2%CVE-2026-17903MEDIUMInsufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment to inEPSS 0.2%CVE-2026-7338HIGHUse after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heapEPSS 0.2%CVE-2023-7258MEDIUMDenial-of-Service in GvisorEPSS 0.2%CVE-2026-11686LOWInsufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had comprEPSS 0.2%CVE-2023-21356—In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execEPSS 0.2%CVE-2025-12906MEDIUMInappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a cEPSS 0.2%CVE-2018-9416CRITICALIn sg_remove_scat of scsi/sg.c, there is a possible memory corruption due to
an unusual root cause. This could lead to local escalation EPSS 0.2%CVE-2026-11145MEDIUMRace in Geolocation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTMEPSS 0.2%