Vulnerabilidades em google
6.748 resultadosAnálise Vexday
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2026-0092CRITICALIn Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalationEPSS 0.2%CVE-2026-14131MEDIUMInsufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had comprEPSS 0.2%CVE-2026-76033MEDIUMInappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2026-5901MEDIUMInsufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a maEPSS 0.2%CVE-2026-14136MEDIUMInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perEPSS 0.2%CVE-2026-7920HIGHUse after free in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentiEPSS 0.2%CVE-2026-14031MEDIUMInappropriate implementation in File Input in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crEPSS 0.2%CVE-2026-14128MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contentEPSS 0.2%CVE-2025-5981MEDIUMArbitrary File write in OSV-SCALIBREPSS 0.2%CVE-2025-1122MEDIUMOut-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gaEPSS 0.2%CVE-2026-13991MEDIUMInsufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perEPSS 0.2%CVE-2026-7923HIGHOut of bounds write in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to poEPSS 0.2%CVE-2026-17867HIGHInsufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform EPSS 0.2%CVE-2025-0087MEDIUMIn onCreate of UninstallerActivity.java, there is a possible way to uninstall a different user's app due to a missing permission check. ThisEPSS 0.2%CVE-2025-11206HIGHHeap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a sandbox escape via EPSS 0.2%CVE-2026-11001MEDIUMInappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage inEPSS 0.2%CVE-2026-14143MEDIUMIncorrect security UI in Passwords in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a craEPSS 0.2%CVE-2018-9350MEDIUMIn ih264d_assign_pic_num of ih264d_utils.c there is a possible out of bound read due to missing bounds check. This could lead to a denial ofEPSS 0.2%CVE-2026-17741HIGHInsufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentEPSS 0.2%CVE-2025-36891HIGHElevation of privilegeEPSS 0.2%