Vulnerabilidades em google
7.001 resultadosAnálise Vexday
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2026-87486MEDIUMClickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar viaEPSS 0.1%CVE-2023-21267—In multiple functions of KeyguardViewMediator.java, there is a possible way to bypass lockdown mode with screen pinning due to a logic errorEPSS 0.1%CVE-2023-48407—there is a possible DCK won't be deleted after factory reset due to a logic error in the code. This could lead to local escalation of privilEPSS 0.1%CVE-2023-21274—In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to locEPSS 0.1%CVE-2023-21334—In App Ops Service, there is a possible disclosure of information about installed packages due to a logic error in the code. This could leadEPSS 0.1%CVE-2018-9486MEDIUMIn hidh_l2cif_data_ind of hidh_conn.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local inforEPSS 0.1%CVE-2022-20264MEDIUMIn Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due to side channel infoEPSS 0.1%CVE-2025-48612HIGHIn setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment settiEPSS 0.1%CVE-2023-21393—In Settings, there is a possible way for the user to change SIM due to a missing permission check. This could lead to local escalation of prEPSS 0.1%CVE-2023-21295—In SliceManagerService, there is a possible way to check if a content provider is installed due to a missing null check. This could lead to EPSS 0.1%CVE-2023-48414—In the Pixel Camera Driver, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privEPSS 0.1%CVE-2023-40116HIGHIn onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions due to a logic error iEPSS 0.1%CVE-2024-31337HIGHIn PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This could lead to localEPSS 0.1%CVE-2025-48615HIGHIn getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could leadEPSS 0.1%CVE-2026-12449HIGHUse after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escaEPSS 0.1%CVE-2026-0029HIGHIn __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2024-49714HIGHIn avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device eEPSS 0.1%CVE-2023-21291—In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing permission check. ThiEPSS 0.1%CVE-2023-48405—there is a possible way for the secure world to write to NS memory due to a logic error in the code. This could lead to local escalation of EPSS 0.1%CVE-2026-79055MEDIUMInformation leak in Sharing in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social engineering to EPSS 0.1%