Vulnerabilidades en Google
7001 resultadosAnálisis Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2026-58846HIGHIn kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation ofEPSS 0.1%CVE-2024-34747HIGHIn DevmemXIntMapPages of devicemem_server.c, there is a possible use-after-free due to a logic error in the code. This could lead to local eEPSS 0.1%CVE-2023-21283—In multiple functions of StatusHints.java, there is a possible way to reveal images across users due to a confused deputy. This could lead tEPSS 0.1%CVE-2026-87723MEDIUMUntrusted Search Path (PATH Hijacking) in fuse-archiveEPSS 0.1%CVE-2026-78892HIGHIncorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system accessEPSS 0.1%CVE-2025-48598MEDIUMIn multiple locations, there is a possible way to alter the primary user's face unlock settings due to a confused deputy. This could lead toEPSS 0.1%CVE-2025-2509HIGHOut-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvEPSS 0.1%CVE-2023-21396—In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation ofEPSS 0.1%CVE-2024-43085HIGHIn handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due toEPSS 0.1%CVE-2025-48582HIGHIn multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an intent redirect. ThiEPSS 0.1%CVE-2026-11241HIGHInsufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment EPSS 0.1%CVE-2023-35675—In loadMediaResumptionControls of MediaResumeListener.kt, there is a possible way to play and listen to media files played by another user oEPSS 0.1%CVE-2023-40130HIGHIn notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. This could lead to locEPSS 0.1%CVE-2024-31310HIGHIn newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service app in the Autofill EPSS 0.1%CVE-2026-93376MEDIUMOut of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read meEPSS 0.1%CVE-2024-34726HIGHIn PVRSRV_MMap of pvr_bridge_k.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local esEPSS 0.1%CVE-2024-0042MEDIUMIn TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead to local bypass of DEPSS 0.1%CVE-2025-26427MEDIUMIn multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privileEPSS 0.1%CVE-2026-58941HIGHIn multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local esEPSS 0.1%CVE-2025-22441HIGHIn getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible way to load arbitrary java code in a privileEPSS 0.1%