Vulnerabilidades em Google
7.001 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2023-21333—In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informatiEPSS 0.1%CVE-2026-0056LOWIn setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local informationEPSS 0.1%CVE-2026-91727HIGHIncorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised EPSS 0.1%CVE-2023-21332—In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informatiEPSS 0.1%CVE-2026-11072HIGHUse after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via a maliciEPSS 0.1%CVE-2023-35669—In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe EPSS 0.1%CVE-2023-21344—In Job Scheduler, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informatiEPSS 0.1%CVE-2024-0020MEDIUMIn onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a EPSS 0.1%CVE-2026-56881HIGHIn enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation ofEPSS 0.1%CVE-2026-0095HIGHIn l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process duEPSS 0.1%CVE-2024-27204HIGHIn tmu_set_gov_active of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation oEPSS 0.1%CVE-2023-21397—In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of priEPSS 0.1%CVE-2024-27219HIGHIn tmu_set_pi of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilEPSS 0.1%CVE-2024-31325HIGHIn multiple locations, there is a possible way to reveal images across users data due to a logic error in the code. This could lead to localEPSS 0.1%CVE-2026-95358MEDIUMIncorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access resEPSS 0.1%CVE-2023-21293—In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, due to side channel inEPSS 0.1%CVE-2023-21387—In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure. ThEPSS 0.1%CVE-2024-0025HIGHIn sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to EPSS 0.1%CVE-2024-27208HIGHthere is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional eEPSS 0.1%CVE-2025-13425LOWDenial of Service in OSV-SCALIBREPSS 0.1%