Vulnerabilidades em Google
7.003 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2025-48604MEDIUMIn multiple locations, there is a possible way to read files from another user due to a missing permission check. This could lead to local iEPSS 0.1%CVE-2026-11158HIGHInsufficient validation of untrusted input in Downloads in Google Chrome on Mac prior to 149.0.7827.53 allowed a local attacker to potentialEPSS 0.1%CVE-2025-22428HIGHIn hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user frEPSS 0.1%CVE-2018-9439HIGHIn __unregister_prot_hook and packet_release of af_packet.c, there is a
possible use-after-free due to improper locking. This could leadEPSS 0.1%CVE-2026-28582LOWIn onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unauthorized access to and modification of device credentials due tEPSS 0.1%CVE-2026-28586LOWIn multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to loEPSS 0.1%CVE-2018-9397HIGHIn WMT_unlocked_ioctl of MTK WMT device driver, there is a possible OOB
write due to a missing bounds check. This could lead to local esEPSS 0.1%CVE-2025-36887HIGHIn wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrect bounds check. ThisEPSS 0.1%CVE-2025-48532HIGHIn markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due to a confused depuEPSS 0.1%CVE-2026-28630LOWIn onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local infEPSS 0.1%CVE-2024-56190HIGHIn wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to loEPSS 0.1%CVE-2024-29783MEDIUMIn tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosEPSS 0.1%CVE-2024-23713HIGHIn migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to impropEPSS 0.1%CVE-2025-36903HIGHIn lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privileEPSS 0.1%CVE-2025-48524MEDIUMIn isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local dEPSS 0.1%CVE-2025-48652HIGHIn performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This coulEPSS 0.1%CVE-2024-32918MEDIUMPermission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization stepsEPSS 0.1%CVE-2018-9374HIGHIn installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege EPSS 0.1%CVE-2023-35692—In getLocationCache of GeoLocation.java, there is a possible way to send a mock location during an emergency call due to improper input valiEPSS 0.1%CVE-2018-9463HIGHIn sw49408_irq_runtime_engine_debug of touch_sw49408.c, there is a possible
out of bounds write due to an incorrect bounds check. This cEPSS 0.1%