Vulnerabilidades en Google
7001 resultadosAnálisis Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2024-40671HIGHIn DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission cheEPSS 0.1%CVE-2025-48650HIGHIn multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalation of privilege witEPSS 0.1%CVE-2026-13914MEDIUMInappropriate implementation in Passwords in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensEPSS 0.1%CVE-2023-40081—In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to a confused deputy. TEPSS 0.1%CVE-2026-18018MEDIUMInappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing vEPSS 0.1%CVE-2024-0034HIGHIn BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This couldEPSS 0.1%CVE-2025-8747HIGHKeras safe_mode bypass allows arbitrary code execution when loading a malicious model.EPSS 0.1%CVE-2024-43763MEDIUMIn build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (prEPSS 0.1%CVE-2024-27213HIGHIn BroadcastSystemMessage of servicemgr.cpp, there is a possible Remote Code Execution due to a use after free. This could lead to local escEPSS 0.1%CVE-2023-35693—In incfs_kill_sb of fs/incfs/vfs.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of prEPSS 0.1%CVE-2023-40092—In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confused deputy. This couEPSS 0.1%CVE-2024-31331HIGHIn setMimeGroup of PackageManagerService.java, there is a possible way to hide the service from Settings due to a logic error in the code. TEPSS 0.1%CVE-2026-0048MEDIUMIn hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This cEPSS 0.1%CVE-2024-31315MEDIUMIn multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the Device & app notificatEPSS 0.1%CVE-2024-40653HIGHIn multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a loEPSS 0.1%CVE-2024-31339HIGHIn multiple functions of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalatioEPSS 0.1%CVE-2023-40089—In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers withoutEPSS 0.1%CVE-2026-17860LOWInsufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to spoof thEPSS 0.1%CVE-2018-9338HIGHIn ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to locaEPSS 0.1%CVE-2026-0014MEDIUMIn isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This coulEPSS 0.1%