Vulnerabilidades em Google
7.003 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2026-106326MEDIUMConfused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions inEPSS 0.1%CVE-2024-29785MEDIUMIn aur_get_state of aurora.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disEPSS 0.1%CVE-2024-56184MEDIUMIn static long dev_send of tipc_dev_ql, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inEPSS 0.1%CVE-2024-32927HIGHIn sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of pEPSS 0.1%CVE-2018-9376HIGHIn rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possible out of bounds write due to an incorreEPSS 0.1%CVE-2024-47032HIGHIn construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead toEPSS 0.1%CVE-2024-40656MEDIUMIn handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused EPSS 0.1%CVE-2025-48607MEDIUMIn multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code. This could lead to locaEPSS 0.1%CVE-2025-48599HIGHIn multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to a missing permissioEPSS 0.1%CVE-2024-34743HIGHIn setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could leaEPSS 0.1%CVE-2025-48632HIGHIn setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the user has disassociated EPSS 0.1%CVE-2018-9369HIGHIn bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local escalation of privilEPSS 0.1%CVE-2024-40669HIGHIn TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additionEPSS 0.1%CVE-2024-40670HIGHIn TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additionEPSS 0.1%CVE-2024-34738HIGHIn multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due EPSS 0.1%CVE-2025-26449MEDIUMIn multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of servicEPSS 0.1%CVE-2024-56186MEDIUMIn closeChannel of secureelementimpl.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local EPSS 0.1%CVE-2024-27233HIGHIn ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of EPSS 0.1%CVE-2018-9449MEDIUMIn process_service_search_attr_rsp of sdp_discovery.cc, there is a possible out of bound read due to a missing bounds check. This could leadEPSS 0.1%CVE-2025-48542MEDIUMIn multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could EPSS 0.1%