Vulnerabilidades em Google
7.001 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2025-27701MEDIUMIn the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_arraEPSS 0.1%CVE-2024-49740MEDIUMIn multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additioEPSS 0.1%CVE-2025-26464HIGHIn executeAppFunction of AppSearchManagerService.java, there is a possible background activity launch due to a logic error in the code. ThisEPSS 0.1%CVE-2024-0041HIGHIn removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This cEPSS 0.1%CVE-2026-49919HIGHIn tt_face_colr_blend_layer of ttcolr.c, there is a possible remote code execution due to an integer overflow. This could lead to local escaEPSS 0.1%CVE-2025-26421MEDIUMIn multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of priviEPSS 0.1%CVE-2026-11308MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malEPSS 0.1%CVE-2023-40125HIGHIn onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. This could lead to locEPSS 0.1%CVE-2023-21241—In rw_i93_send_to_upper of rw_i93.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalatioEPSS 0.1%CVE-2023-40120HIGHIn multiple locations, there is a possible way to bypass user notification of foreground services due to improper input validation. This couEPSS 0.1%CVE-2026-58726MEDIUMIn FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of pEPSS 0.1%CVE-2018-9379MEDIUMIn multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. ThisEPSS 0.1%CVE-2026-56889MEDIUMIn multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalation of privilege wiEPSS 0.1%CVE-2025-48634HIGHIn relayoutWindow of WindowManagerService.java, there is a possible tapjack attack due to a missing permission check. This could lead to locEPSS 0.1%CVE-2026-58718MEDIUMIn smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead toEPSS 0.1%CVE-2026-57006MEDIUMIn acfw_ffa.c, there is a possible secret read due to a logic error in the code. This could lead to local information disclosure with SystemEPSS 0.1%CVE-2026-56907MEDIUMIn VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalation of privilege with EPSS 0.1%CVE-2025-48585MEDIUMIn multiple functions of ProfilingService.java, there is a possible persistent denial of service due to improper input validation. This coulEPSS 0.1%CVE-2026-56888MEDIUMIn multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead to local escalationEPSS 0.1%CVE-2023-21380—In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with SEPSS 0.1%