Vulnerabilidades em Google

7.001 resultados
Análise Vexday

Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.

CVE-2025-0080HIGHIn multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overlay attack. This coulEPSS 0.1%CVE-2026-11229MEDIUMInappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation EPSS 0.1%CVE-2024-29749HIGHIn tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatioEPSS 0.1%CVE-2025-26425MEDIUMIn multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This couEPSS 0.1%CVE-2025-32349HIGHIn multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack. This could lead to local escalation of pEPSS 0.1%CVE-2023-40135—In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead toEPSS 0.1%CVE-2026-58739MEDIUMIn platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to locEPSS 0.1%CVE-2026-56879MEDIUMIn gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy. This could lead to local escalation of pEPSS 0.1%CVE-2025-26454HIGHIn validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another user due to a confusedEPSS 0.1%CVE-2025-48596HIGHIn appendFrom of Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of prEPSS 0.1%CVE-2023-21300—In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informatEPSS 0.1%CVE-2025-32323HIGHIn getCallingAppName of Shared.java, there is a possible way to trick users into granting file access via deceptive text in a permission popEPSS 0.1%CVE-2023-21299—In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informaEPSS 0.1%CVE-2023-21384—In Package Manager, there is a possible possible permissions bypass due to an unsafe PendingIntent. This could lead to local information disEPSS 0.1%CVE-2026-56950MEDIUMIn validate_ns_buf of mbu_class.rs, there is a possible information disclosure due to improper input validation. This could lead to local inEPSS 0.1%CVE-2023-40139—In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local informatiEPSS 0.1%CVE-2025-48640HIGHIn multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to reEPSS 0.1%CVE-2024-47030MEDIUMAndroid before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-315191818.EPSS 0.1%CVE-2026-58721MEDIUMIn multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information discEPSS 0.1%CVE-2023-21328—In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permissiEPSS 0.1%