Vulnerabilities in google
7,001 resultsCVE-2026-0055MEDIUMIn createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid dirEPSS 0.1%CVE-2023-40080—In multiple functions of btm_ble_gap.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local EPSS 0.1%CVE-2023-40093MEDIUMIn multiple files, there is a possible way that trimmed content could be included in PDF output due to a logic error in the code. This couldEPSS 0.1%CVE-2017-13317MEDIUMIn HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input validation. This could EPSS 0.1%CVE-2026-16416CRITICALInteger overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape viaEPSS 0.1%CVE-2025-48566HIGHIn multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege withEPSS 0.1%CVE-2017-13318MEDIUMIn HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remoEPSS 0.1%CVE-2026-79084MEDIUMInadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging sEPSS 0.1%CVE-2022-20531—In Telecom, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disEPSS 0.1%CVE-2026-18011LOWInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker to obtain potentiallyEPSS 0.1%CVE-2023-45781—In parse_gap_data of utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information diEPSS 0.1%CVE-2026-7351LOWRace in MHTML in Google Chrome prior to 147.0.7727.138 allowed an attacker who convinced a user to install a malicious extension to leak croEPSS 0.1%CVE-2025-0086MEDIUMIn onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could leaEPSS 0.1%CVE-2026-13863HIGHInsufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perfEPSS 0.1%CVE-2026-14060HIGHInsufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perfEPSS 0.1%CVE-2026-19143HIGHInsufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentEPSS 0.1%CVE-2026-17861HIGHInsufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowed a local attacker to perform OS-level pEPSS 0.1%CVE-2026-17973MEDIUMInappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitivEPSS 0.1%CVE-2026-13927HIGHInsufficient validation of untrusted input in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privEPSS 0.1%CVE-2023-21244MEDIUMIn visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead EPSS 0.1%