Vulnerabilidades em Google

7.001 resultados
Análise Vexday

Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.

CVE-2026-87467HIGHRace condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary coEPSS 0.1%CVE-2025-48527MEDIUMIn multiple locations, there is a possible way to leak hidden work profile notifications due to a logic error in the code. This could lead tEPSS 0.1%CVE-2024-25991LOWIn acpm_tmu_ipc_handler of tmu_plugin.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local infoEPSS 0.1%CVE-2024-31334MEDIUMIn DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This coEPSS 0.1%CVE-2026-87554HIGHRace condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outsidEPSS 0.1%CVE-2025-32331HIGHIn showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error in the code. This couEPSS 0.1%CVE-2026-79057HIGHRace condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to poteEPSS 0.1%CVE-2023-48399—In ProtocolMiscATCommandAdapter::Init() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. ThEPSS 0.1%CVE-2023-21375—In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to local escalation of privilege with no aEPSS 0.1%CVE-2026-0021HIGHIn hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible cross-user permission bypass due to a confused deputy. ThisEPSS 0.1%CVE-2024-31336HIGHIn PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution due to improper input validation. This EPSS 0.1%CVE-2026-7994HIGHInappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level pEPSS 0.1%CVE-2023-48411—In SignalStrengthAdapter::FillGsmSignalStrength() of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing boundsEPSS 0.1%CVE-2025-22406HIGHIn bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. This could lead to lEPSS 0.1%CVE-2025-48531HIGHIn getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. This could lead to loEPSS 0.1%CVE-2025-0079HIGHIn multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error in the code. This couEPSS 0.1%CVE-2026-7932MEDIUMInsufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local attacker to bypass navigation restrictiEPSS 0.1%CVE-2025-48522HIGHIn setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code.EPSS 0.1%CVE-2025-22425MEDIUMIn onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalatiEPSS 0.1%CVE-2023-35677—In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could leaEPSS 0.1%