Vulnerabilidades en Google

7001 resultados
Análisis Vexday

Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.

CVE-2022-20264MEDIUMIn Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel infoEPSS 0.1%CVE-2024-49714HIGHIn avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device eEPSS 0.1%CVE-2026-79286HIGHMissing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arEPSS 0.1%CVE-2026-12449HIGHUse after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escaEPSS 0.1%CVE-2026-87525LOWOut of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sEPSS 0.1%CVE-2026-14094HIGHUse after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalaEPSS 0.1%CVE-2023-40116HIGHIn onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error iEPSS 0.1%CVE-2023-21291—In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing permission check. ThiEPSS 0.1%CVE-2026-79055MEDIUMInformation leak in Sharing in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to EPSS 0.1%CVE-2023-40128—In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalatEPSS 0.1%CVE-2023-48405—there is a possible way for the secure world to write to NS memory due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2023-21295—In SliceManagerService, there is a possible way to check if a content provider is installed due to a missing null check. This could lead to EPSS 0.1%CVE-2023-21343—In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to local escalation of prEPSS 0.1%CVE-2026-95302LOWIncorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin datEPSS 0.1%CVE-2023-21256—In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. ThisEPSS 0.1%CVE-2024-34721MEDIUMIn ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. EPSS 0.1%CVE-2023-21243—In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due EPSS 0.1%CVE-2026-102317HIGHImproper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute EPSS 0.1%CVE-2024-34731HIGHIn multiple functions of TranscodingResourcePolicy.cpp, there is a possible memory corruption due to a race condition. This could lead to loEPSS 0.1%CVE-2024-34720HIGHIn com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_ZygoteCommandBuffer.cpp, there is a possible EPSS 0.1%