Vulnerabilities in google
7,001 resultsCVE-2026-0083CRITICALIn Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local escalation of privileEPSS 0.1%CVE-2026-0046MEDIUMIn InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attacEPSS 0.1%CVE-2026-106306MEDIUMIncorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions viEPSS 0.1%CVE-2024-27223MEDIUMIn EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check.EPSS 0.1%CVE-2021-30605—Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects EPSS 0.1%CVE-2023-21337HIGHIn InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informationEPSS 0.1%CVE-2026-0106CRITICALIn vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of pEPSS 0.1%CVE-2023-45780HIGHIn Print Service, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of prEPSS 0.1%CVE-2021-39810HIGHIn verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app withEPSS 0.1%CVE-2026-5889MEDIUMCryptographic Flaw in PDFium in Google Chrome prior to 147.0.7727.55 allowed an attacker to read potentially sensitive information from encrEPSS 0.1%CVE-2024-0035HIGHIn onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null checkEPSS 0.1%CVE-2024-0053LOWIn getCustomPrinterIcon of PrintManagerService.java, there is a possible way to view other user's images due to a confused deputy. This coulEPSS 0.1%CVE-2023-35680—In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. This could lead to locaEPSS 0.1%CVE-2026-18018MEDIUMInappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing vEPSS 0.1%CVE-2024-40671HIGHIn DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission cheEPSS 0.1%CVE-2026-13914MEDIUMInappropriate implementation in Passwords in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensEPSS 0.1%CVE-2025-8747HIGHKeras safe_mode bypass allows arbitrary code execution when loading a malicious model.EPSS 0.1%CVE-2026-106192MEDIUMInformation leak in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via phEPSS 0.1%CVE-2025-48650HIGHIn multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalation of privilege witEPSS 0.1%CVE-2026-106367HIGHMissing authorization in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineeringEPSS 0.1%