Vulnerabilidades en Google
7001 resultadosAnálisis Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2026-78949LOWObservable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin dEPSS 0.1%CVE-2024-23698HIGHIn RGXFWChangeOSidPriority of rgxfwutils.c, there is a possible arbitrary code execution due to a missing bounds check. This could lead to lEPSS 0.1%CVE-2024-49739MEDIUMIn MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation ofEPSS 0.1%CVE-2026-95316LOWUnchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a locaEPSS 0.1%CVE-2025-48635HIGHIn multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. ThiEPSS 0.1%CVE-2024-40658HIGHIn getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to EPSS 0.1%CVE-2025-48614MEDIUMIn rebootWipeUserData of RecoverySystem.java, there is a possible way to factory reset the device while in DSU mode due to a missing permissEPSS 0.1%CVE-2026-58679HIGHIn gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. This could lead to locaEPSS 0.1%CVE-2025-48623HIGHIn init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalatiEPSS 0.1%CVE-2024-29741HIGHIn pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation ofEPSS 0.1%CVE-2026-78936LOWObservable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin dEPSS 0.1%CVE-2024-31318HIGHIn CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permissioEPSS 0.1%CVE-2023-21252—In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to improper input validatiEPSS 0.1%CVE-2024-32923MEDIUMthere is a possible cellular denial of service due to a logic error in the code. This could lead to remote denial of service with no additioEPSS 0.1%CVE-2024-56188MEDIUMthere is a possible way to crash the modem due to a missing null check. This could lead to remote denial of service with no additional execuEPSS 0.1%CVE-2025-27700HIGHThere is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no adEPSS 0.1%CVE-2026-10998MEDIUMOut of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of boEPSS 0.1%CVE-2023-48421HIGHIn gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/platform/pixel/pixel_gpu_slc.c, there is a possiblEPSS 0.1%CVE-2025-48638HIGHIn __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalaEPSS 0.1%CVE-2023-21389—In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalationEPSS 0.1%