Vulnerabilidades em Google

7.001 resultados
Análise Vexday

Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.

CVE-2024-31335HIGHIn DevmemIntChangeSparse2 of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lEPSS 0.1%CVE-2026-0083CRITICALIn Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local escalation of privileEPSS 0.1%CVE-2023-21266HIGHIn multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a permissions bypass. EPSS 0.1%CVE-2023-40098—In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user due to a logic erroEPSS 0.1%CVE-2026-0097HIGHIn multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead toEPSS 0.1%CVE-2026-11157MEDIUMScript injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious exEPSS 0.1%CVE-2026-28648HIGHIn Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additiEPSS 0.1%CVE-2024-31328HIGHIn broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from the background on thEPSS 0.1%CVE-2026-28640HIGHIn checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input EPSS 0.1%CVE-2021-30605—Inappropriate implementation in the ChromeOS Readiness Tool installer on Windows prior to 1.0.2.0 loosens DCOM access rights on two objects EPSS 0.1%CVE-2026-0046MEDIUMIn InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attacEPSS 0.1%CVE-2024-27223MEDIUMIn EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check.EPSS 0.1%CVE-2026-0106CRITICALIn vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of pEPSS 0.1%CVE-2023-21337HIGHIn InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informationEPSS 0.1%CVE-2024-0035HIGHIn onNullBinding of TileLifecycleManager.java, there is a possible way to launch an activity from the background due to a missing null checkEPSS 0.1%CVE-2021-39810HIGHIn verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactless payment app withEPSS 0.1%CVE-2026-5889MEDIUMCryptographic Flaw in PDFium in Google Chrome prior to 147.0.7727.55 allowed an attacker to read potentially sensitive information from encrEPSS 0.1%CVE-2023-45780HIGHIn Print Service, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of prEPSS 0.1%CVE-2024-0053LOWIn getCustomPrinterIcon of PrintManagerService.java, there is a possible way to view other user's images due to a confused deputy. This coulEPSS 0.1%CVE-2023-35680—In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. This could lead to locaEPSS 0.1%