Vulnerabilidades em Google
7.001 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2023-21145—In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in tEPSS 0.1%CVE-2023-21231—In getIntentForButton of ButtonManager.java, there is a possible way for an unprivileged application to start a non-exported or permission-pEPSS 0.1%CVE-2023-40131HIGHIn GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilegEPSS 0.1%CVE-2023-21352—In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additiEPSS 0.1%CVE-2025-32333HIGHIn startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lEPSS 0.1%CVE-2023-21357—In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System exEPSS 0.1%CVE-2025-0082MEDIUMIn multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across users due to a confuseEPSS 0.1%CVE-2025-22434HIGHIn handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the code. This could leaEPSS 0.1%CVE-2025-48591MEDIUMIn multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local iEPSS 0.1%CVE-2025-48594HIGHIn onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges after disassociation EPSS 0.1%CVE-2023-21280—In setMediaButtonBroadcastReceiver of MediaSessionRecord.java, there is a possible permanent DoS due to resource exhaustion. This could leadEPSS 0.1%CVE-2023-21306—In ContentService, there is a possible way to read installed sync content providers due to side channel information disclosure. This could lEPSS 0.1%CVE-2023-40100HIGHIn discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalEPSS 0.1%CVE-2023-21240—In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additEPSS 0.1%CVE-2025-36929MEDIUMIn AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. This could lead to loEPSS 0.1%CVE-2018-9377HIGHIn getIntentForIntentSender of ActivityManagerService.java, there is a possible way to access user metadata due to a pending intent. This coEPSS 0.1%CVE-2023-21378—In Telecomm, there is a possible way to silence the ring for calls of secondary users due to a missing permission check. This could lead to EPSS 0.1%CVE-2025-48606HIGHIn preparePackage of InstallPackageHelper.java, there is a possible way for an app to appear hidden upon installation without a mechanism toEPSS 0.1%CVE-2024-34737HIGHIn ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip wEPSS 0.1%CVE-2023-21368—In Audio, there is a possible out of bounds read due to missing bounds check. This could lead to local information disclosure with no additiEPSS 0.1%