Vulnerabilidades em google
7.003 resultadosAnálise Vexday
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2026-17993HIGHRace in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious EPSS 0.1%CVE-2024-34733HIGHIn DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. This could lead to locEPSS 0.1%CVE-2018-9477HIGHIn the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This coEPSS 0.1%CVE-2026-28631HIGHIn buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could leadEPSS 0.1%CVE-2026-58848HIGHIn multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalEPSS 0.1%CVE-2025-48636HIGHIn openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path traversal error. ThEPSS 0.1%CVE-2026-28663HIGHIn buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL BypassEPSS 0.1%CVE-2023-21313—In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could lead to local escalatEPSS 0.1%CVE-2023-21297—In SEPolicy, there is a possible way to access the factory MAC address due to a permissions bypass. This could lead to local information disEPSS 0.1%CVE-2026-28620HIGHIn multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of priviEPSS 0.1%CVE-2024-34748HIGHIn _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to locaEPSS 0.1%CVE-2026-106313MEDIUMIncorrect authorization in Browser in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineerEPSS 0.1%CVE-2018-9474HIGHIn writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This coulEPSS 0.1%CVE-2018-9370HIGHIn download.c there is a special mode allowing user to download data into memory and causing possible memory corruptions due to missing bounEPSS 0.1%CVE-2025-48613HIGHIn VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previously signed with the EPSS 0.1%CVE-2025-26440HIGHIn multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This EPSS 0.1%CVE-2026-28614HIGHIn onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalaEPSS 0.1%CVE-2025-26431HIGHIn setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility service due to a logicEPSS 0.1%CVE-2024-27211HIGHIn AtiHandleAPOMsgType of ati_Main.c, there is a possible OOB write due to a missing null check. This could lead to local escalation of privEPSS 0.1%CVE-2026-106254MEDIUMInformation leak in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information viEPSS 0.1%