Vulnerabilidades em Google

7.001 resultados
Análise Vexday

Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.

CVE-2026-19143HIGHInsufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentEPSS 0.1%CVE-2023-21244MEDIUMIn visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead EPSS 0.1%CVE-2025-0086MEDIUMIn onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could leaEPSS 0.1%CVE-2026-14060HIGHInsufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perfEPSS 0.1%CVE-2025-32330MEDIUMIn generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio stream due to an insecuEPSS 0.1%CVE-2026-0008HIGHIn multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could lead to local escalatiEPSS 0.1%CVE-2023-40079—In injectSendIntentSender of ShortcutService.java, there is a possible background activity launch due to a permissions bypass. This could leEPSS 0.1%CVE-2026-15115LOWInsufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker toEPSS 0.1%CVE-2023-40097—In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to improper input validation. This could lead toEPSS 0.1%CVE-2023-40095—In createDontSendToRestrictedAppsBundle of PendingIntentUtils.java, there is a possible background activity launch due to a missing check. TEPSS 0.1%CVE-2026-28625HIGHIn multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%CVE-2025-48580HIGHIn connectInternal of MediaBrowser.java, there is a possible way to access while in use permission while the app is in background due to a lEPSS 0.1%CVE-2026-49895LOWIn get_eht_operation_channel_width of ieee802_11_common.c, there is a possible out of bounds read due to an incorrect bounds check. This couEPSS 0.1%CVE-2026-28647HIGHIn updateState of DeviceAdminAppsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This couEPSS 0.1%CVE-2024-0048HIGHIn Session of AccountManagerService.java, there is a possible method to retain foreground service privileges due to incorrect handling of nuEPSS 0.1%CVE-2023-40091—In onTransact of IncidentService.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation EPSS 0.1%CVE-2024-0050HIGHIn getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a missing validation check. This could leadEPSS 0.1%CVE-2026-17877HIGHInappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level priEPSS 0.1%CVE-2026-28641HIGHIn shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic eEPSS 0.1%CVE-2026-17996MEDIUMInappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypass navigation restricEPSS 0.1%