Vulnerabilidades em Google
7.003 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2025-36889MEDIUMIn onCreateTasks of CameraActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local informatioEPSS 0.1%CVE-2026-0069MEDIUMIn verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local deniaEPSS 0.1%CVE-2026-0067MEDIUMIn multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in EPSS 0.1%CVE-2026-0070MEDIUMIn multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input vaEPSS 0.1%CVE-2026-28641HIGHIn shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic eEPSS 0.1%CVE-2024-34725HIGHIn DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to locaEPSS 0.1%CVE-2026-0085MEDIUMIn applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. EPSS 0.1%CVE-2026-0079MEDIUMIn multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This couldEPSS 0.1%CVE-2026-0060MEDIUMIn updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root caEPSS 0.1%CVE-2026-0152HIGHIn OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system call to system call to maliciously expand the VMA out of boundEPSS 0.1%CVE-2026-0099HIGHIn onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in theEPSS 0.1%CVE-2025-48641HIGHIn multiple functions of Nfc.h, there is a possible use after free due to a race condition. This could lead to local escalation of privilegeEPSS 0.1%CVE-2026-28647HIGHIn updateState of DeviceAdminAppsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This couEPSS 0.1%CVE-2026-56923MEDIUMIn handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition. This could lead to local escalationEPSS 0.1%CVE-2026-56964MEDIUMIn multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with SysEPSS 0.1%CVE-2023-20942—In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a EPSS 0.1%CVE-2024-49724HIGHIn multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a EPSS 0.1%CVE-2026-56915MEDIUMIn bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition. This could lead to local escalation ofEPSS 0.1%CVE-2026-28667MEDIUMIn multiple functions of rw_t5t.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local informatiEPSS 0.1%CVE-2026-56988MEDIUMIn multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition. This could lead to local escalation oEPSS 0.1%