Vulnerabilidades em Google
7.001 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2023-35687—In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to local escalation of EPSS 0.2%CVE-2026-11216MEDIUMIncorrect security UI in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specEPSS 0.2%CVE-2026-17919MEDIUMInsufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege eEPSS 0.2%CVE-2023-21392—In Bluetooth, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege when conneEPSS 0.2%CVE-2026-17927MEDIUMInsufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a maEPSS 0.2%CVE-2023-7261HIGHInappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalationEPSS 0.2%CVE-2026-8005MEDIUMInsufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment EPSS 0.2%CVE-2025-13097MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox EPSS 0.2%CVE-2026-91708LOWRace condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtaEPSS 0.2%CVE-2026-87571MEDIUMImproper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering toEPSS 0.2%CVE-2023-40103—In multiple locations, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege withEPSS 0.2%CVE-2025-12446MEDIUMIncorrect security UI in SplitView in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in speciEPSS 0.2%CVE-2026-67180HIGHGoogle Turbinia arbitrary command executionEPSS 0.2%CVE-2026-11214MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-originEPSS 0.2%CVE-2026-12018HIGHInappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilEPSS 0.2%CVE-2025-13634MEDIUMInappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to bypass mark of the EPSS 0.2%CVE-2024-47020MEDIUMAndroid before 2024-10-05 on Google Pixel devices allows information disclosure in the ABL component, A-331966488.EPSS 0.2%CVE-2024-0033HIGHIn multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead to local escalationEPSS 0.2%CVE-2024-47022MEDIUMAndroid before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-331255656.EPSS 0.2%CVE-2026-11291MEDIUMInappropriate implementation in Android Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to bypass sameEPSS 0.2%