Vulnerabilidades en Google

6748 resultados
Análisis Vexday

Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.

CVE-2026-11668MEDIUMUninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data EPSS 0.2%CVE-2026-11696MEDIUMUninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer prEPSS 0.2%CVE-2026-11038MEDIUMInsufficient policy enforcement in Subresource Integrity in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass contentEPSS 0.2%CVE-2026-0128MEDIUMIn RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote informatioEPSS 0.2%CVE-2026-79117MEDIUMRace condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeriEPSS 0.2%CVE-2026-16481MEDIUMServer-Side Request Forgery (SSRF) and Credential Exfiltration in googleapis/mcp-toolbox cloud-healthcare-fhir-fetch-page ToolEPSS 0.2%CVE-2025-48611CRITICALIn DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation oEPSS 0.2%CVE-2026-91739MEDIUMMissing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renEPSS 0.2%CVE-2024-7021MEDIUMInappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofingEPSS 0.2%CVE-2024-8912HIGHHTTP Request Smuggling in LookerEPSS 0.2%CVE-2026-11682HIGHInappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker who had compromised the reEPSS 0.2%CVE-2026-8009MEDIUMInappropriate implementation in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer procEPSS 0.2%CVE-2026-91713MEDIUMMissing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process EPSS 0.2%CVE-2026-28615CRITICALIn Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalationEPSS 0.2%CVE-2025-0649HIGHStack Exhaustion In Tensorflow ServingEPSS 0.2%CVE-2026-17776MEDIUMPolicy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to poteEPSS 0.2%CVE-2024-32911HIGHThere is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additioEPSS 0.2%CVE-2026-87517LOWRace condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypassEPSS 0.2%CVE-2026-17737MEDIUMUse after free in Bluetooth in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer prEPSS 0.2%CVE-2026-87628HIGHUse after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside thEPSS 0.2%