Vulnerabilidades em Google
6.748 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2026-14418MEDIUMUninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML paEPSS 0.2%CVE-2026-17890MEDIUMInsufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisedEPSS 0.2%CVE-2026-8539MEDIUMScript injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts oEPSS 0.2%CVE-2026-7950MEDIUMOut of bounds read and write in GFX in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform arbitrary read/write via maEPSS 0.2%CVE-2026-9971MEDIUMInappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engageEPSS 0.2%CVE-2026-7953MEDIUMInsufficient validation of untrusted input in Omnibox in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary EPSS 0.2%CVE-2026-17893MEDIUMInsufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had comprEPSS 0.2%CVE-2026-28652LOWIn multiple functions of RangingServiceImpl.java, there is a possible MITM due to a missing permission check. This could lead to remote infoEPSS 0.2%CVE-2026-7942MEDIUMInteger overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML pagEPSS 0.2%CVE-2026-17809MEDIUMInsufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisEPSS 0.2%CVE-2026-14538MEDIUMBigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP ToolboxEPSS 0.2%CVE-2025-4690MEDIUMAngularJS 'linky' filter ReDoSEPSS 0.2%CVE-2026-13884HIGHInteger overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via malicious netwEPSS 0.2%CVE-2025-12440MEDIUMInappropriate implementation in Autofill in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage inEPSS 0.2%CVE-2026-13034MEDIUMInappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the rendereEPSS 0.2%CVE-2026-17806MEDIUMInsufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromisEPSS 0.2%CVE-2026-13021MEDIUMInappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass sEPSS 0.2%CVE-2026-17908MEDIUMInsufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had EPSS 0.2%CVE-2026-17736MEDIUMInsufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had cEPSS 0.2%CVE-2026-7962MEDIUMInsufficient policy enforcement in DirectSockets in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform arbitrary readEPSS 0.2%