Vulnerabilidades en Google

7001 resultados
Análisis Vexday

Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.

CVE-2026-9987HIGHInsufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker toEPSS 0.1%CVE-2026-13929MEDIUMInsufficient policy enforcement in DevTools in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass navigationEPSS 0.1%CVE-2026-11267MEDIUMInsufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a EPSS 0.1%CVE-2025-26443HIGHIn parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due to EPSS 0.1%CVE-2026-17716HIGHUse after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via maliciEPSS 0.1%CVE-2023-3497—Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to peEPSS 0.1%CVE-2025-1121MEDIUMPrivilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physicEPSS 0.1%CVE-2018-9481MEDIUMIn bta_hd_set_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote infoEPSS 0.1%CVE-2025-48565HIGHIn multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the code. This could lead tEPSS 0.1%CVE-2026-17699HIGHUse after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a malicEPSS 0.1%CVE-2026-95315HIGHUse after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the saEPSS 0.1%CVE-2026-11148MEDIUMInappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin daEPSS 0.1%CVE-2026-15905HIGHUse after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a maliciEPSS 0.1%CVE-2026-11212MEDIUMInsufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a maEPSS 0.1%CVE-2025-36909MEDIUMInformation disclosureEPSS 0.1%CVE-2026-17862HIGHUse after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2026-12456MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a maEPSS 0.1%CVE-2026-14018HIGHUse after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2023-35668—In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to EPSS 0.1%CVE-2026-0124CRITICALThere is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional eEPSS 0.1%