Vulnerabilidades em Google
7.001 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2024-27226HIGHIn tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of EPSS 0.1%CVE-2025-48526MEDIUMIn createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActivity in another profEPSS 0.1%CVE-2018-9366HIGHIn IMSA_Recv_Thread and VT_IMCB_Thread of ImsaClient.cpp and VideoTelephony.c, there is a possible out of bounds write due to an integer oveEPSS 0.1%CVE-2025-36920HIGHIn hyp_alloc of arch/arm64/kvm/hyp/nvhe/alloc.c, there is a possible out of bounds write due to improper input validation. This could lead tEPSS 0.1%CVE-2025-48644MEDIUMIn multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial ofEPSS 0.1%CVE-2026-56958MEDIUMIn gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to localEPSS 0.1%CVE-2018-9372HIGHIn cmd_flash_mmc_sparse_img of dl_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to a loEPSS 0.1%CVE-2026-19139HIGHRace in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalaEPSS 0.1%CVE-2024-25984MEDIUMIn dumpBatteryDefend of dump_power.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local inforEPSS 0.1%CVE-2023-21257—In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing peEPSS 0.1%CVE-2025-26422MEDIUMIn dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permissionEPSS 0.1%CVE-2025-48559MEDIUMIn multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input validation. This could EPSS 0.1%CVE-2023-21269—In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL byEPSS 0.1%CVE-2023-21364—In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in theEPSS 0.1%CVE-2023-21309—In libcore, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no adEPSS 0.1%CVE-2024-53841HIGHIn startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation EPSS 0.1%CVE-2023-21323—In Activity Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informEPSS 0.1%CVE-2026-28614HIGHIn onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalaEPSS 0.1%CVE-2025-32332HIGHIn multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with EPSS 0.1%CVE-2024-22012HIGHthere is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional eEPSS 0.1%