Vulnerabilidades em Google
7.003 resultadosAnálise Vexday
Com 4.763 CVEs catalogadas e 77 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Google é 3,6 vezes superior à média geral do catálogo, sinalizando risco operacional elevado para organizações que dependem desse ecossistema. O volume de 1.225 CVEs surgidas nos últimos 90 dias indica cadência intensa de descobertas, exigindo ciclos de patching ágeis. O tipo de falha mais recorrente é CWE-416 (use-after-free), classe de vulnerabilidade que frequentemente viabiliza execução de código arbitrário e escalada de privilégios. Destaque especial para CVE-2023-4863, com EPSS de 0,9974 — valor próximo ao máximo possível —, indicando probabilidade altíssima de exploração ativa e merecendo tratamento prioritário imediato.
CVE-2026-28671LOWIn updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local infoEPSS 0.1%CVE-2024-43766MEDIUMIn multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remEPSS 0.1%CVE-2025-48608MEDIUMIn isValidMediaUri of SettingsProvider.java, there is a possible cross user media read due to a missing permission check. This could lead toEPSS 0.1%CVE-2024-47025MEDIUMIn ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could lead to local inforEPSS 0.1%CVE-2026-55270HIGHIn dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation oEPSS 0.1%CVE-2026-58859HIGHIn multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege wiEPSS 0.1%CVE-2026-58701HIGHIn trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalatEPSS 0.1%CVE-2025-48575HIGHIn multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass. This could lead toEPSS 0.1%CVE-2026-28648HIGHIn Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additiEPSS 0.1%CVE-2026-0050LOWIn handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This couEPSS 0.1%CVE-2026-0153HIGHIn Write of msg_to_host_buffer.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalaEPSS 0.1%CVE-2025-26418HIGHIn setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account toEPSS 0.1%CVE-2026-58854HIGHIn multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with noEPSS 0.1%CVE-2026-0098HIGHIn getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could EPSS 0.1%CVE-2026-58724HIGHIn multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with SysEPSS 0.1%CVE-2026-58734HIGHIn google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalEPSS 0.1%CVE-2025-48648MEDIUMIn isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denEPSS 0.1%CVE-2026-58728HIGHIn ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege withEPSS 0.1%CVE-2026-0089HIGHIn multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check.EPSS 0.1%CVE-2026-0091HIGHIn multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could leadEPSS 0.1%