Vulnerabilidades em Google
7.001 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2023-21278—In multiple locations, there is a possible way to obscure the microphone privacy indicator due to a logic error in the code. This could leadEPSS 0.1%CVE-2023-40124MEDIUMIn multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photEPSS 0.1%CVE-2024-27231MEDIUMIn tmu_get_tr_stats of tmu.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disEPSS 0.1%CVE-2024-34748HIGHIn _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to locaEPSS 0.1%CVE-2026-106279HIGHIncorrect reference resolution in Passwords in Google Chrome on on iOS prior to 155.0.8059.39 allowed a local attacker who had compromised tEPSS 0.1%CVE-2018-9368MEDIUMIn mtkscoaudio debugfs there is a possible arbitrary kernel memory write due to missing bounds check and weakened SELinux policies. This couEPSS 0.1%CVE-2023-21304—In Content Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informaEPSS 0.1%CVE-2026-58848HIGHIn multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalEPSS 0.1%CVE-2026-28607HIGHIn multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could leadEPSS 0.1%CVE-2026-28620HIGHIn multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of priviEPSS 0.1%CVE-2023-21373—In Telephony, there is a possible way for a guest user to change the preferred SIM due to a missing permission check. This could lead to locEPSS 0.1%CVE-2023-35653—In TBD of TBD, there is a possible way to access location information due to a permissions bypass. This could lead to local information discEPSS 0.1%CVE-2023-21297—In SEPolicy, there is a possible way to access the factory MAC address due to a permissions bypass. This could lead to local information disEPSS 0.1%CVE-2025-26440HIGHIn multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This EPSS 0.1%CVE-2026-17993HIGHRace in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious EPSS 0.1%CVE-2026-28644HIGHIn startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could EPSS 0.1%CVE-2023-35667—In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a lEPSS 0.1%CVE-2025-26431HIGHIn setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logicEPSS 0.1%CVE-2025-48636HIGHIn openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path traversal error. ThEPSS 0.1%CVE-2025-48613HIGHIn VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previously signed with the EPSS 0.1%