Vulnerabilidades em Google
7.003 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2025-26432MEDIUMIn multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could lead to local denialEPSS 0.1%CVE-2025-22414HIGHIn FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permission check. This coulEPSS 0.1%CVE-2024-56187MEDIUMIn ppcfw_deny_sec_dram_access of ppcfw.c, there is a possible arbitrary read from TEE memory due to a logic error in the code. This could leEPSS 0.1%CVE-2024-53836MEDIUMIn wbrc_bt_dev_write of wb_regon_coordinator.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local eEPSS 0.1%CVE-2025-26434MEDIUMIn libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additioEPSS 0.1%CVE-2024-29757HIGHthere is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additioEPSS 0.1%CVE-2024-43769HIGHIn isPackageDeviceAdmin of PackageManagerService.java, there is a possible edge case which could prevent the uninstallation of CloudDpc due EPSS 0.1%CVE-2025-22439HIGHIn onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps due to a missing perEPSS 0.1%CVE-2024-32901HIGHIn v4l2_smfc_qbuf of smfc-v4l2-ioctls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escEPSS 0.1%CVE-2024-47017HIGHIn ufshc_scsi_cmd of ufs.c, there is a possible stack variable use after free due to a use after free. This could lead to local escalation oEPSS 0.1%CVE-2025-22417HIGHIn finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacking/overlay attack. TEPSS 0.1%CVE-2024-34724HIGHIn _UnrefAndMaybeDestroy of pmr.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalationEPSS 0.1%CVE-2025-48597HIGHIn multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could leEPSS 0.1%CVE-2025-22431MEDIUMIn multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limited circumstances due EPSS 0.1%CVE-2026-0189HIGHIn ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2026-0107HIGHIn gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. This could lead to locEPSS 0.1%CVE-2024-40664MEDIUMIn setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility service due to a logiEPSS 0.1%CVE-2024-29784HIGHIn prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escaEPSS 0.1%CVE-2025-26461LOWIn Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the user attempts to closEPSS 0.1%CVE-2025-26429MEDIUMIn collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to locEPSS 0.1%