Vulnerabilidades em Google
7.001 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2025-36901HIGHWLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.EPSS 0.2%CVE-2024-44097CRITICALAccording to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validaEPSS 0.2%CVE-2026-17844MEDIUMInsufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment EPSS 0.2%CVE-2024-32909HIGHIn handle_msg of main.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of priEPSS 0.2%CVE-2026-7961MEDIUMInsufficient validation of untrusted input in Permissions in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network sEPSS 0.2%CVE-2018-9423MEDIUMIn ihevcd_parse_slice_header of ihevcd_parse_slice_header.c there is a possible out of bound read due to missing bounds check. This could leEPSS 0.2%CVE-2025-1079HIGHRCE In Google Web DesignerEPSS 0.2%CVE-2026-14119MEDIUMType Confusion in Bluetooth in Google Chrome on Windows prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain poEPSS 0.2%CVE-2026-0037HIGHIn multiple functions of ffa.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation EPSS 0.2%CVE-2026-14048MEDIUMUse after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially EPSS 0.2%CVE-2026-13879MEDIUMUse after free in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sEPSS 0.2%CVE-2026-0063CRITICALIn setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a logic error in the codEPSS 0.2%CVE-2026-0071CRITICALIn SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilEPSS 0.2%CVE-2026-0030HIGHIn __host_check_page_state_range of mem_protect.c, there is a possible out of bounds write due to an incorrect bounds check. This could leadEPSS 0.2%CVE-2026-12032LOWInappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised EPSS 0.2%CVE-2026-0028HIGHIn __pkvm_host_share_guest of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local esEPSS 0.2%CVE-2026-0031HIGHIn multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalatEPSS 0.2%CVE-2025-48618MEDIUMIn processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to improper locking. TEPSS 0.2%CVE-2024-34741HIGHIn setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaEPSS 0.2%CVE-2026-11219MEDIUMInappropriate implementation in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictioEPSS 0.2%