Vulnerabilidades em Google

7.001 resultados
Análise Vexday

Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.

CVE-2026-28656HIGHIn multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to lEPSS 0.1%CVE-2026-28578MEDIUMIn multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. ThisEPSS 0.1%CVE-2025-32326HIGHIn multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent security check due to a confused deputy. ThEPSS 0.1%CVE-2026-28617MEDIUMIn add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denialEPSS 0.1%CVE-2025-48576MEDIUMIn updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanent denial of service EPSS 0.1%CVE-2025-22438HIGHIn afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local escalation of priviEPSS 0.1%CVE-2025-48603MEDIUMIn InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to lEPSS 0.1%CVE-2026-0009HIGHIn multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege witEPSS 0.1%CVE-2025-48547HIGHIn multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead to local escalation EPSS 0.1%CVE-2025-48536HIGHIn grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to modify secure settingsEPSS 0.1%CVE-2025-32347HIGHIn onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. TEPSS 0.1%CVE-2024-40651HIGHIn TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the EPSS 0.1%CVE-2023-21348—In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informatEPSS 0.1%CVE-2024-22009HIGHIn init_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege wiEPSS 0.1%CVE-2024-40649HIGHIn TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege in the EPSS 0.1%CVE-2024-32903HIGHIn prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead EPSS 0.1%CVE-2024-34734HIGHIn onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to disable the active VPN app from the lockscreen EPSS 0.1%CVE-2018-9482MEDIUMIn intr_data_copy_cb of btif_hd.cc, there is a possible out of bounds read due to an integer overflow. This could lead to local information EPSS 0.1%CVE-2025-48627HIGHIn startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to launch an activity from the background due to a EPSS 0.1%CVE-2023-21382—In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to a missing permissioEPSS 0.1%