Vulnerabilidades em Google
7.001 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2018-9371HIGHIn the Mediatek Preloader, there are out of bounds reads and writes due to an exposed interface that allows arbitrary peripheral memory mappEPSS 0.1%CVE-2023-21247—In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restrictEPSS 0.1%CVE-2026-0198MEDIUMIn is_pd_allowed of gem_msg.c, there is a possible permission bypass due to a missing permission check. This could lead to local informationEPSS 0.1%CVE-2026-28602HIGHIn setClipboardAccessNotificationsEnabledForUser of ClipboardService.java, there is a possible mult-iuser isolation due to a logic error in EPSS 0.1%CVE-2024-49728MEDIUMIn generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused deputy. This could lEPSS 0.1%CVE-2023-21326—In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channelEPSS 0.1%CVE-2025-48610MEDIUMIn __pkvm_guest_relinquish_to_host of mem_protect.c, there is a possible configuration data leak due to a logic error in the code. This coulEPSS 0.1%CVE-2025-48537HIGHIn multiple locations, there is a possible way to persistently DoS the device due to improper input validation. This could lead to local infEPSS 0.1%CVE-2025-48546HIGHIn checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This couldEPSS 0.1%CVE-2023-21376MEDIUMIn Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosurEPSS 0.1%CVE-2023-21312—In IntentResolver, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with EPSS 0.1%CVE-2024-27209HIGHthere is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional eEPSS 0.1%CVE-2023-21248—In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction dEPSS 0.1%CVE-2025-22437HIGHIn setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due to a logic error in EPSS 0.1%CVE-2026-11297HIGHInsufficient validation of untrusted input in Reader Mode in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to bypEPSS 0.1%CVE-2025-32345HIGHIn updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary userEPSS 0.1%CVE-2023-21302—In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informaEPSS 0.1%CVE-2025-48523HIGHIn onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. ThisEPSS 0.1%CVE-2023-21367—In Scudo, there is a possible way to exploit certain heap OOB read/write issues due to an insecure implementation/design. This could lead toEPSS 0.1%CVE-2017-13323HIGHIn String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privEPSS 0.1%