Vulnerabilidades en google
7001 resultadosAnálisis Vexday
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2026-12457MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderEPSS 0.1%CVE-2023-40074—In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privilegeEPSS 0.1%CVE-2026-0011HIGHIn enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the codeEPSS 0.1%CVE-2026-17932MEDIUMUse after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive iEPSS 0.1%CVE-2024-0014HIGHIn startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead toEPSS 0.1%CVE-2026-57012HIGHIn the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of pEPSS 0.1%CVE-2026-11062MEDIUMInsufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a EPSS 0.1%CVE-2026-87514HIGHUse after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via aEPSS 0.1%CVE-2023-40073—In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to local information diEPSS 0.1%CVE-2026-0005MEDIUMIn onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction witEPSS 0.1%CVE-2026-12463MEDIUMInappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the reEPSS 0.1%CVE-2024-0021HIGHIn onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification liEPSS 0.1%CVE-2024-0038HIGHIn injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing pEPSS 0.1%CVE-2023-40094—In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This coulEPSS 0.1%CVE-2026-14540HIGHServer-Side Request Forgery via Unrestricted HTTP Redirection in MCP ToolboxEPSS 0.1%CVE-2023-20910MEDIUMIn add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead tEPSS 0.1%CVE-2024-0051HIGHIn onQueueFilled of SoftMPEG4.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalatioEPSS 0.1%CVE-2024-31326HIGHIn multiple locations, there is a possible way in which policy migration code will never be executed due to a logic error in the code. This EPSS 0.1%CVE-2026-79245HIGHUse after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the renderer process to execute arEPSS 0.1%CVE-2025-48621HIGHIn DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This could lead to local EPSS 0.1%