Vulnerabilidades em Google

7.001 resultados
Análise Vexday

Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.

CVE-2024-31316HIGHIn onResult of AccountManagerService.java, there is a possible way to perform an arbitrary background activity launch due to parcel mismatchEPSS 0.1%CVE-2024-0024HIGHIn multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input vaEPSS 0.1%CVE-2024-34729HIGHIn multiple locations, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation ofEPSS 0.1%CVE-2024-43087HIGHIn getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in tEPSS 0.1%CVE-2025-48622MEDIUMIn ProcessArea of dng_misc_opcodes.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local informatioEPSS 0.1%CVE-2023-0460MEDIUMRemote code execution in YouTube Android Player API SDKEPSS 0.1%CVE-2023-48407—there is a possible DCK won't be deleted after factory reset due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%CVE-2018-9486MEDIUMIn hidh_l2cif_data_ind of hidh_conn.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local inforEPSS 0.1%CVE-2023-21274—In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to locEPSS 0.1%CVE-2023-21267—In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic errorEPSS 0.1%CVE-2023-21334—In App Ops Service, there is a possible disclosure of information about installed packages due to a logic error in the code. This could leadEPSS 0.1%CVE-2026-87486MEDIUMClickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar viaEPSS 0.1%CVE-2023-21393—In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to local escalation of prEPSS 0.1%CVE-2026-13844HIGHUse after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2025-48612HIGHIn setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment settiEPSS 0.1%CVE-2026-13827HIGHUse after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a maliEPSS 0.1%CVE-2025-48615HIGHIn getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could leadEPSS 0.1%CVE-2023-48414—In the Pixel Camera Driver, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privEPSS 0.1%CVE-2026-0029HIGHIn __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2024-31337HIGHIn PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This could lead to localEPSS 0.1%