Vulnerabilidades em Google
7.001 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2026-58751MEDIUMIn multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalaEPSS 0.1%CVE-2026-55304MEDIUMIn addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to localEPSS 0.1%CVE-2018-9384MEDIUMIn multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local information disclosureEPSS 0.1%CVE-2023-21329—In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to EPSS 0.1%CVE-2025-36918HIGHIn aoc_service_read_message of aoc_ipc_core.c, there is a possible out of bounds read due to improper input validation. This could lead to lEPSS 0.1%CVE-2023-35670HIGHIn computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private directories due to a patEPSS 0.1%CVE-2024-31332HIGHIn multiple locations, there is a possible way to bypass a restriction on adding new Wi-Fi connections due to a missing permission check. ThEPSS 0.1%CVE-2026-55302MEDIUMIn multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%CVE-2025-48639HIGHIn DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking/overlay attack. ThiEPSS 0.1%CVE-2023-40110MEDIUMIn multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escaEPSS 0.1%CVE-2026-45520HIGHIn onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escEPSS 0.1%CVE-2023-40117HIGHIn resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This could lead to localEPSS 0.1%CVE-2026-0017HIGHIn onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could leadEPSS 0.1%CVE-2018-9464HIGHIn multiple locations, there is a possible way to read protected files due to a missing permission check. This could lead to local escalatioEPSS 0.1%CVE-2025-48578HIGHIn multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a missing permisEPSS 0.1%CVE-2026-58755MEDIUMIn smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead tEPSS 0.1%CVE-2026-58765MEDIUMIn GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with SystemEPSS 0.1%CVE-2026-56973MEDIUMIn multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2018-9387HIGHIn multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an integer overflow. This could lead to local eEPSS 0.1%CVE-2024-23711HIGHIn DevmemXIntUnreserveRange of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This couldEPSS 0.1%