Vulnerabilidades em Google
7.001 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2026-0011HIGHIn enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the codeEPSS 0.1%CVE-2024-0014HIGHIn startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead toEPSS 0.1%CVE-2026-12457MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderEPSS 0.1%CVE-2023-40074—In saveToXml of PersistableBundle.java, invalid data could lead to local persistent denial of service with no additional execution privilegeEPSS 0.1%CVE-2026-17932MEDIUMUse after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive iEPSS 0.1%CVE-2026-57012HIGHIn the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of pEPSS 0.1%CVE-2026-11062MEDIUMInsufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a EPSS 0.1%CVE-2023-40073—In visitUris of Notification.java, there is a possible cross-user media read due to Confused Deputy. This could lead to local information diEPSS 0.1%CVE-2026-87514HIGHUse after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via aEPSS 0.1%CVE-2023-40094—In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This coulEPSS 0.1%CVE-2026-12463MEDIUMInappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the reEPSS 0.1%CVE-2024-0021HIGHIn onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to enable notification liEPSS 0.1%CVE-2024-31326HIGHIn multiple locations, there is a possible way in which policy migration code will never be executed due to a logic error in the code. This EPSS 0.1%CVE-2024-0038HIGHIn injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing pEPSS 0.1%CVE-2024-0051HIGHIn onQueueFilled of SoftMPEG4.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalatioEPSS 0.1%CVE-2026-0005MEDIUMIn onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction witEPSS 0.1%CVE-2026-14540HIGHServer-Side Request Forgery via Unrestricted HTTP Redirection in MCP ToolboxEPSS 0.1%CVE-2023-20910MEDIUMIn add of WifiNetworkSuggestionsManager.java, there is a possible way to trigger permanent DoS due to resource exhaustion. This could lead tEPSS 0.1%CVE-2026-17966MEDIUMInappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitivEPSS 0.1%CVE-2026-11309MEDIUMInsufficient policy enforcement in History in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crEPSS 0.1%