Vulnerabilidades em google

7.001 resultados
Análise Vexday

Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.

CVE-2026-14094HIGHUse after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalaEPSS 0.1%CVE-2026-13844HIGHUse after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalatiEPSS 0.1%CVE-2026-13827HIGHUse after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a maliEPSS 0.1%CVE-2026-106326MEDIUMConfused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions inEPSS 0.1%CVE-2023-40128—In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalatEPSS 0.1%CVE-2026-87525LOWOut of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sEPSS 0.1%CVE-2026-79286HIGHMissing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arEPSS 0.1%CVE-2024-34731HIGHIn multiple functions of TranscodingResourcePolicy.cpp, there is a possible memory corruption due to a race condition. This could lead to loEPSS 0.1%CVE-2023-21256—In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via Settings due to a logic error in the code. ThisEPSS 0.1%CVE-2026-102317HIGHImproper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute EPSS 0.1%CVE-2023-21243—In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due EPSS 0.1%CVE-2026-95302LOWIncorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin datEPSS 0.1%CVE-2024-34720HIGHIn com_android_internal_os_ZygoteCommandBuffer_nativeForkRepeatedly of com_android_internal_os_ZygoteCommandBuffer.cpp, there is a possible EPSS 0.1%CVE-2026-91727HIGHIncorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised EPSS 0.1%CVE-2026-0056LOWIn setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local informationEPSS 0.1%CVE-2023-21333—In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informatiEPSS 0.1%CVE-2023-21343—In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to local escalation of prEPSS 0.1%CVE-2024-34721MEDIUMIn ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. EPSS 0.1%CVE-2023-21332—In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informatiEPSS 0.1%CVE-2023-21387—In User Backup Manager, there is a possible way to leak a token to bypass user confirmation for backup due to log information disclosure. ThEPSS 0.1%