Vulnerabilidades em Google
7.001 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2023-40134—In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local infEPSS 0.1%CVE-2024-43086MEDIUMIn validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to aEPSS 0.1%CVE-2026-0115LOWIn Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could lead to physical inforEPSS 0.1%CVE-2023-35657MEDIUMIn bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information dEPSS 0.1%CVE-2023-21385—In Whitechapel, there is a possible out of bounds read due to memory corruption. This could lead to local information disclosure with no addEPSS 0.1%CVE-2024-22007MEDIUMIn constraint_check of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disEPSS 0.1%CVE-2024-47027HIGHIn sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. EPSS 0.1%CVE-2023-21355—In libaudioclient, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with noEPSS 0.1%CVE-2026-106340MEDIUMMissing authorization in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to obtain sensitiEPSS 0.1%CVE-2023-21271—In parseInputs of ShimPreparedModel.cpp, there is a possible out of bounds read due to improper input validation. This could lead to local iEPSS 0.1%CVE-2024-29743HIGHIn tmu_set_temp_lut of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of EPSS 0.1%CVE-2025-48584MEDIUMIn multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limits causing resource EPSS 0.1%CVE-2026-91717MEDIUMMissing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive informatEPSS 0.1%CVE-2024-29753HIGHIn tmu_set_control_temp_step of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalEPSS 0.1%CVE-2023-21245HIGHIn showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a possible way to access the lock screen during deviEPSS 0.1%CVE-2026-0018MEDIUMIn multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validationEPSS 0.1%CVE-2024-29754MEDIUMIn TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure EPSS 0.1%CVE-2023-21289—In multiple locations, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local inforEPSS 0.1%CVE-2025-48553HIGHIn handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device admin due to a logic error in the code. ThiEPSS 0.1%CVE-2023-21379—In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the BEPSS 0.1%