Vulnerabilidades em google
6.721 resultadosAnálise Vexday
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2026-17936MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage inEPSS 0.2%CVE-2023-48419CRITICALAn attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in EoPEPSS 0.2%CVE-2026-14539MEDIUMDenial of Service via Unrestricted Payload Buffering in MCP ToolboxEPSS 0.2%CVE-2026-17846MEDIUMInappropriate implementation in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the rEPSS 0.2%CVE-2024-22004CRITICALUnchecked length in Trusted Application on Google Nest Wifi Pro, leading to out of bounds readEPSS 0.2%CVE-2026-13868MEDIUMInappropriate implementation in Network in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised theEPSS 0.2%CVE-2026-17852MEDIUMInappropriate implementation in Media Router in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy EPSS 0.2%CVE-2026-13838MEDIUMInappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a craEPSS 0.2%CVE-2026-87599MEDIUMImproper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafEPSS 0.2%CVE-2023-40087—In transcodeQ*ToFloat of btif_avrcp_audio_track.cc, there is a possible out of bounds write due to a missing bounds check. This could lead tEPSS 0.2%CVE-2026-87501MEDIUMUI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML EPSS 0.2%CVE-2026-87523MEDIUMRace condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain senEPSS 0.2%CVE-2026-87445MEDIUMUI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML paEPSS 0.2%CVE-2026-79225MEDIUMIncorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeEPSS 0.2%CVE-2026-9739CRITICALVulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `alloweEPSS 0.2%CVE-2026-95364MEDIUMImproper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted EPSS 0.2%CVE-2026-87562MEDIUMIncorrect reference resolution in Accessibility in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially sEPSS 0.2%CVE-2026-7915MEDIUMInsufficient data validation in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker to bypass navigation rEPSS 0.2%CVE-2026-91725MEDIUMObservable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted EPSS 0.2%CVE-2026-95363MEDIUMUI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof EPSS 0.2%