Vulnerabilidades en google
7001 resultadosAnálisis Vexday
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2025-48650HIGHIn multiple locations, there is a possible information disclosure due to SQL injection. This could lead to local escalation of privilege witEPSS 0.1%CVE-2025-8747HIGHKeras safe_mode bypass allows arbitrary code execution when loading a malicious model.EPSS 0.1%CVE-2026-13914MEDIUMInappropriate implementation in Passwords in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensEPSS 0.1%CVE-2024-0034HIGHIn BackgroundLaunchProcessController, there is a possible way to launch arbitrary activity from the background due to BAL Bypass. This couldEPSS 0.1%CVE-2024-40671HIGHIn DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission cheEPSS 0.1%CVE-2023-40081—In loadMediaDataInBgForResumption of MediaDataManager.kt, there is a possible way to view another user's images due to a confused deputy. TEPSS 0.1%CVE-2026-18018MEDIUMInappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing vEPSS 0.1%CVE-2024-31331HIGHIn setMimeGroup of PackageManagerService.java, there is a possible way to hide the service from Settings due to a logic error in the code. TEPSS 0.1%CVE-2026-0048MEDIUMIn hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This cEPSS 0.1%CVE-2024-40653HIGHIn multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a loEPSS 0.1%CVE-2023-35693—In incfs_kill_sb of fs/incfs/vfs.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of prEPSS 0.1%CVE-2024-31315MEDIUMIn multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the Device & app notificatEPSS 0.1%CVE-2023-40092—In verifyShortcutInfoPackage of ShortcutService.java, there is a possible way to see another user's image due to a confused deputy. This couEPSS 0.1%CVE-2024-27213HIGHIn BroadcastSystemMessage of servicemgr.cpp, there is a possible Remote Code Execution due to a use after free. This could lead to local escEPSS 0.1%CVE-2024-43763MEDIUMIn build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (prEPSS 0.1%CVE-2026-17860LOWInsufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to spoof thEPSS 0.1%CVE-2026-13955LOWInsufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perfEPSS 0.1%CVE-2023-48409—In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/mali_kbase_core_linux.c, there is a possible out oEPSS 0.1%CVE-2024-31339HIGHIn multiple functions of StatsService.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalatioEPSS 0.1%CVE-2023-40089—In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers withoutEPSS 0.1%