Vulnerabilidades em Google
6.710 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2023-35652—In ProtocolEmergencyCallListIndAdapter::Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds checEPSS 0.3%CVE-2025-9867MEDIUMInappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofinEPSS 0.3%CVE-2025-3074MEDIUMInappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a craEPSS 0.3%CVE-2026-78960MEDIUMInformation leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain croEPSS 0.3%CVE-2026-9892HIGHInappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the rEPSS 0.3%CVE-2026-13872CRITICALInsufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to EPSS 0.3%CVE-2026-17816HIGHInsufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised tEPSS 0.3%CVE-2026-87534MEDIUMMissing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineeriEPSS 0.3%CVE-2026-10960HIGHUninitialized Use in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to poEPSS 0.3%CVE-2026-11279HIGHOut of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox EPSS 0.3%CVE-2026-0902HIGHInappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform an out of bounds memory readEPSS 0.3%CVE-2026-55318HIGHIn multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additionEPSS 0.3%CVE-2026-0171HIGHIn multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution wiEPSS 0.3%CVE-2026-13974HIGHInteger overflow in Safe Browsing in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictionsEPSS 0.3%CVE-2020-15983—Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content securityEPSS 0.3%CVE-2023-40122MEDIUMIn applyCustomDescription of SaveUi.java, there is a possible way to view other user's images due to a confused deputy. This could lead to lEPSS 0.3%CVE-2026-5282HIGHOut of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read vEPSS 0.3%CVE-2026-95284CRITICALBuffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside tEPSS 0.3%CVE-2025-4051MEDIUMInsufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage inEPSS 0.3%CVE-2026-87601HIGHRace condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crEPSS 0.3%