Vulnerabilidades em google
7.003 resultadosAnálise Vexday
Google registra presença mínima no panorama de risco com apenas 4 vulnerabilidades na base, nenhuma sob exploração ativa (KEV) e apenas 1 crítica identificada. A fraqueza dominante relaciona-se a validação inadequada de entrada (CWE-20), indicando risco controlado e sem pressão temporal dado que não há publicações nos últimos 90 dias.
CVE-2018-9404HIGHIn oemCallback of ril.cpp, there is a possible out of bounds write due to an
integer overflow. This could lead to local escalation of prEPSS 0.1%CVE-2025-48524MEDIUMIn isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local dEPSS 0.1%CVE-2026-0045HIGHIn bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. TEPSS 0.1%CVE-2024-44098HIGHIn lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free. This could lead to EPSS 0.1%CVE-2024-34743HIGHIn setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could leaEPSS 0.1%CVE-2024-40659MEDIUMIn getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation featEPSS 0.1%CVE-2025-48601MEDIUMIn multiple locations, there is a possible permanent denial of service due to improper input validation. This could lead to local escalationEPSS 0.1%CVE-2024-34738HIGHIn multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due EPSS 0.1%CVE-2018-9428HIGHIn startDevice of AAudioServiceStreamBase.cpp there is a possible out of bounds write due to a use after free. This could lead to local arbiEPSS 0.1%CVE-2024-32927HIGHIn sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of pEPSS 0.1%CVE-2025-48599HIGHIn multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to a missing permissioEPSS 0.1%CVE-2023-40105MEDIUMIn backupAgentCreated of ActivityManagerService.java, there is a possible way to leak sensitive data due to a missing permission check. ThisEPSS 0.1%CVE-2024-56184MEDIUMIn static long dev_send of tipc_dev_ql, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local inEPSS 0.1%CVE-2024-31327MEDIUMIn multiple functions of MessageQueueBase.h, there is a possible out of bounds write due to a race condition. This could lead to local escalEPSS 0.1%CVE-2018-9376HIGHIn rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possible out of bounds write due to an incorreEPSS 0.1%CVE-2025-36900MEDIUMIn lwis_test_register_io of lwis_device_test.c, there is a possible OOB Write due to an integer overflow. This could lead to local escalatioEPSS 0.1%CVE-2026-0077HIGHIn resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the cEPSS 0.1%CVE-2025-32346HIGHIn onActivityResult of VoicemailSettingsActivity.java, there is a possible work profile contact number leak due to a confused deputy. This cEPSS 0.1%CVE-2026-106326MEDIUMConfused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions inEPSS 0.1%CVE-2024-29785MEDIUMIn aur_get_state of aurora.c, there is a possible information disclosure due to uninitialized data. This could lead to local information disEPSS 0.1%