Vulnerabilidades em google
7.001 resultadosAnálise Vexday
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2023-2626HIGHAuthentication Bypass in OpenThread Boarder Router devicesEPSS 0.1%CVE-2024-34723MEDIUMIn onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from background due to a logiEPSS 0.1%CVE-2025-48567HIGHIn multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrecEPSS 0.1%CVE-2024-0036HIGHIn startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities fEPSS 0.1%CVE-2024-40660HIGHIn setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a logic error in the codEPSS 0.1%CVE-2026-0059HIGHIn multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead EPSS 0.1%CVE-2025-48605HIGHIn multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the code. This could lead EPSS 0.1%CVE-2024-34719HIGHIn multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local escalation of privilege EPSS 0.1%CVE-2025-48602HIGHIn exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic erroEPSS 0.1%CVE-2024-49722MEDIUMIn showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy. This could lead to EPSS 0.1%CVE-2026-0061MEDIUMIn multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay aEPSS 0.1%CVE-2025-48616LOWIn multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning due to a logic erroEPSS 0.1%CVE-2026-0012MEDIUMIn setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This coulEPSS 0.1%CVE-2025-32327HIGHIn multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to SQL injection. This could lead to local esEPSS 0.1%CVE-2023-21283—In multiple functions of StatusHints.java, there is a possible way to reveal images across users due to a confused deputy. This could lead tEPSS 0.1%CVE-2026-58846HIGHIn kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation ofEPSS 0.1%CVE-2024-34747HIGHIn DevmemXIntMapPages of devicemem_server.c, there is a possible use-after-free due to a logic error in the code. This could lead to local eEPSS 0.1%CVE-2025-2509HIGHOut-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvEPSS 0.1%CVE-2026-87723MEDIUMUntrusted Search Path (PATH Hijacking) in fuse-archiveEPSS 0.1%CVE-2026-78892HIGHIncorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system accessEPSS 0.1%