Vulnerabilities in google

7,001 results
Vexday analysis

Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.

CVE-2026-7338HIGHUse after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heapEPSS 0.2%CVE-2025-12906MEDIUMInappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a cEPSS 0.2%CVE-2026-10004MEDIUMInsufficient validation of untrusted input in Passwords in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform UI spoEPSS 0.2%CVE-2026-11161MEDIUMInappropriate implementation in DataTransfer in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data viaEPSS 0.2%CVE-2026-0013HIGHIn setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This couldEPSS 0.2%CVE-2026-11156MEDIUMInappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafteEPSS 0.2%CVE-2018-20072HIGHInsufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform out of bounds memory access EPSS 0.2%CVE-2018-9416CRITICALIn sg_remove_scat of scsi/sg.c, there is a possible memory corruption due to an unusual root cause. This could lead to local escalation EPSS 0.2%CVE-2026-15432HIGHObservable Timing Discrepancy in Tink-Java and Tink-Android ChunkedMacVerificationEPSS 0.2%CVE-2026-11145MEDIUMRace in Geolocation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTMEPSS 0.2%CVE-2024-43090MEDIUMIn multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disEPSS 0.2%CVE-2026-11155MEDIUMInappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafteEPSS 0.2%CVE-2026-17927MEDIUMInsufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a maEPSS 0.2%CVE-2026-106328MEDIUMIncorrect authorization in PDF in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering EPSS 0.2%CVE-2026-11216MEDIUMIncorrect security UI in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specEPSS 0.2%CVE-2023-35687—In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to local escalation of EPSS 0.2%CVE-2026-17919MEDIUMInsufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege eEPSS 0.2%CVE-2026-106251MEDIUMUI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineeringEPSS 0.2%CVE-2023-7261HIGHInappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalationEPSS 0.2%CVE-2026-106316MEDIUMUI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineeringEPSS 0.2%