16,977 known vulnerabilities
Top Products
In ccd, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit
In ccd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege
In widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local informati
Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an attacker who convinced a user to install
Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially ex
Use after free in WebRTC in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap
Use after free in WebTransport in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit
In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local es
In setUclampMinLocked of PowerSessionManager.cpp, there is a possible way to corrupt memory due to a use after free. Thi
In (TBD) of (TBD), there is a possible way to bypass the lockscreen due to Biometric Auth Failure. This could lead to lo
In exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to
In setMimeGroup of PackageManagerService.java, there is a possible crash loop due to resource exhaustion. This could lea
In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically grant accessibility ser
In queue of UsbRequest.java, there is a possible way to corrupt memory due to a use after free. This could lead to local
In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation due to a logic error i
In getMainActivityLaunchIntent of LauncherAppsService.java, there is a possible way to bypass the restrictions on starti
In addOrReplacePhoneAccount of PhoneAccountRegistrar.java, there is a possible way to enable a phone account without use
In onCreate of PhoneAccountSettingsActivity.java and related files, there is a possible way to mislead the user into ena
In onActivityResult of AvatarPickerActivity.java, there is a possible way to access images belonging to other users due
In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. Th
In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent misma
In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could
In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. T
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource
In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resou
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource
In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of bounds read due to t
The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" bu
In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resourc
The PowerVR GPU kernel driver maintains an "Information Page" used by its cache subsystem. This page can only be written
In onCreate of MasterClearConfirmFragment.java, there is a possible factory reset due to a tapjacking/overlay attack. Th
In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overl
In ApplicationsDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This
Insufficient policy enforcement in CORS in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to leak cross-
Inappropriate implementation in in File System API in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote a
Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a rem
Heap buffer overflow in libphonenumber in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to potentially
Heap buffer overflow in Platform Apps in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed an attacker who convi
Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote at
Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a mal
Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a mal
Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remot
Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remot
Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to b
Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote at
Heap buffer overflow in Network Service in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user
Use after free in Overview Mode in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed a remote attacker who convi
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started