Vulnerabilidades em google
7.003 resultadosAnálise Vexday
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2026-56958MEDIUMIn gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to localEPSS 0.1%CVE-2023-21269—In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL byEPSS 0.1%CVE-2018-9372HIGHIn cmd_flash_mmc_sparse_img of dl_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to a loEPSS 0.1%CVE-2025-48526MEDIUMIn createMultiProfilePagerAdapter of ChooserActivity.java , there is a possible way for an app to launch the ChooserActivity in another profEPSS 0.1%CVE-2024-23710HIGHIn assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privilegEPSS 0.1%CVE-2025-26422MEDIUMIn dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permissionEPSS 0.1%CVE-2026-106405MEDIUMRace condition in CustomTabs in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass web origin policy via EPSS 0.1%CVE-2025-48528MEDIUMIn multiple locations, there is a possible way to overlay biometrics due to a tapjacking/overlay attack. This could lead to local escalationEPSS 0.1%CVE-2023-21309—In libcore, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no adEPSS 0.1%CVE-2023-21369—In Usage Access, there is a possible way to display a Settings usage access restriction toggle screen due to a permissions bypass. This coulEPSS 0.1%CVE-2024-27236HIGHIn aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilegEPSS 0.1%CVE-2025-36899HIGHThere is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation ofEPSS 0.1%CVE-2023-21364—In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial of service in theEPSS 0.1%CVE-2024-32908HIGHIn sec_media_protect of media.c, there is a possible permission bypass due to a race condition. This could lead to local escalation of priviEPSS 0.1%CVE-2024-27205HIGHthere is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional executionEPSS 0.1%CVE-2023-21257—In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing peEPSS 0.1%CVE-2024-25985HIGHIn bigo_unlocked_ioctl of bigo.c, there is a possible UAF due to a missing bounds check. This could lead to local escalation of privilege wiEPSS 0.1%CVE-2018-9370HIGHIn download.c there is a special mode allowing user to download data into memory and causing possible memory corruptions due to missing bounEPSS 0.1%CVE-2023-21354—In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions, due to side channelEPSS 0.1%CVE-2018-9477HIGHIn the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This coEPSS 0.1%