Vulnerabilidades en google
7003 resultadosCVE-2024-29744MEDIUMIn tmu_get_gov_time_windows, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discEPSS 0.1%CVE-2026-28603HIGHIn assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confusedEPSS 0.1%CVE-2025-48533HIGHIn multiple locations, there is a possible way to use apps linked from a context menu of a lockscreen app due to a race condition. This coulEPSS 0.1%CVE-2026-28572HIGHIn onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation oEPSS 0.1%CVE-2025-48563HIGHIn onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could leadEPSS 0.1%CVE-2026-0019HIGHIn SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation oEPSS 0.1%CVE-2024-27232MEDIUMIn asn1_ec_pkey_parse of asn1_common.c, there is a possible OOB read due to a missing null check. This could lead to local information disclEPSS 0.1%CVE-2023-21270HIGHIn restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revokeEPSS 0.1%CVE-2025-48573HIGHIn sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service while the app is in the background due tEPSS 0.1%CVE-2023-21349—In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informaEPSS 0.1%CVE-2024-27237MEDIUMIn wipe_ns_memory of nsmemwipe.c, there is a possible incorrect size calculation due to a logic error in the code. This could lead to local EPSS 0.1%CVE-2026-28600HIGHIn onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead toEPSS 0.1%CVE-2026-28577HIGHIn addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to localEPSS 0.1%CVE-2023-35664—In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to locEPSS 0.1%CVE-2025-36908MEDIUMIn lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to lEPSS 0.1%CVE-2026-28578MEDIUMIn multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. ThisEPSS 0.1%CVE-2026-28633MEDIUMIn initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion.EPSS 0.1%CVE-2025-36898HIGHThere is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additEPSS 0.1%CVE-2025-13437MEDIUMArbitrary node_modules Directory Deletion in Google zxEPSS 0.1%CVE-2023-21317—In ContentService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informatEPSS 0.1%