Vulnerabilidades em Google
7.001 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2024-31311MEDIUMIn increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a missing bounds check. This could lead to loEPSS 0.1%CVE-2024-23707HIGHIn multiple locations, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of priviEPSS 0.1%CVE-2026-0032HIGHIn multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local eEPSS 0.1%CVE-2023-40138—In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local informatiEPSS 0.1%CVE-2026-28613HIGHIn initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation. This couldEPSS 0.1%CVE-2025-32329HIGHIn multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic errEPSS 0.1%CVE-2023-40123—In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could EPSS 0.1%CVE-2025-22433HIGHIn canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most commonly used in Work ProfEPSS 0.1%CVE-2024-27220HIGHIn lpm_req_handler of , there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation oEPSS 0.1%CVE-2024-43084MEDIUMIn visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information diEPSS 0.1%CVE-2023-40137—In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead EPSS 0.1%CVE-2025-36932HIGHIn tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validatiEPSS 0.1%CVE-2023-21279—In visitUris of RemoteViews.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information dEPSS 0.1%CVE-2026-58698MEDIUMIn ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalEPSS 0.1%CVE-2025-32328HIGHIn multiple functions of Session.java, there is a possible way to view images belonging to a different user of the device due to a logic errEPSS 0.1%CVE-2023-40111HIGHIn setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending intent on behalf of system_server due to a cEPSS 0.1%CVE-2025-22432MEDIUMIn notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input validation. This could leEPSS 0.1%CVE-2026-7941MEDIUMInsufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to inject aEPSS 0.1%CVE-2025-48630HIGHIn drawLayersInternal of SkiaRenderEngine.cpp, there is a possible way to access the GPU cache due to side channel information disclosure. TEPSS 0.1%CVE-2023-21235—In onCreate of LockSettingsActivity.java, there is a possible way set a new lockscreen PIN without entering the existing PIN due to a permisEPSS 0.1%