Vulnerabilidades em Google

7.001 resultados
Análise Vexday

Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.

CVE-2025-48552HIGHIn saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from persistence due to a logic error in the EPSS 0.1%CVE-2026-28599HIGHIn addCreatorToken of ActivityManagerService.java, there is a possible Intent Redirection Bypass due to a logic error in the code. This coulEPSS 0.1%CVE-2026-28650HIGHIn setHiddenWhileSuspended of WindowState.java, there is a possible overlay bypass due to a logic error in the code. This could lead to locaEPSS 0.1%CVE-2026-28658HIGHIn findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation EPSS 0.1%CVE-2023-35676—In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafEPSS 0.1%CVE-2024-31313HIGHIn availableToWriteBytes of MessageQueueBase.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead toEPSS 0.1%CVE-2025-48653HIGHIn loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in the code. This could EPSS 0.1%CVE-2026-11269HIGHInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to eEPSS 0.1%CVE-2026-28655HIGHIn multiple functions of RemoteViews.java, there is a possible background activity launch bypass due to a logic error in the code. This coulEPSS 0.1%CVE-2025-48525HIGHIn disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications when not associated toEPSS 0.1%CVE-2023-21341HIGHIn Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This could lead to local esEPSS 0.1%CVE-2024-29740HIGHIn tmu_set_table of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of priEPSS 0.1%CVE-2026-58678HIGHIn Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege withEPSS 0.1%CVE-2026-55359HIGHIn multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%CVE-2025-48654HIGHIn onStart of CompanionDeviceManagerService.java, there is a possible confused deputy due to a logic error in the code. This could lead to lEPSS 0.1%CVE-2026-56970HIGHIn multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of priviEPSS 0.1%CVE-2026-58691HIGHIn FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of prEPSS 0.1%CVE-2024-0019MEDIUMIn setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due EPSS 0.1%CVE-2023-35659HIGHIn DevmemIntChangeSparse of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could leEPSS 0.1%CVE-2025-26426MEDIUMIn BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" packEPSS 0.1%