16,977 known vulnerabilities
Top Products
In isp, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privileg
In hevc decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalat
In keyinstall, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation o
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In mdp, there is a possible out of bounds write due to incorrect error handling. This could lead to local escalation of
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-ori
Use after free in Browser History in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially explo
Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the r
Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote atta
Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker wh
Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass X
Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attac
Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac
Out of bounds read in WebUI Settings in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform an out
Use after free in FileAPI in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sand
Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause
When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink
During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially ex
When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this co
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to b
When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note
Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed un
When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone nu
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have
An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScri
If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This coul
In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network add requests due to
In fdt_path_offset_namelen of fdt_ro.c, there is a possible out of bounds read due to an incorrect bounds check. This co
In phNxpNciHal_core_initialized of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check
In a query in MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead
In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible privilege escalation due to improper input validat
In Pixel firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local inform
In mmu_map_for_fw of gs_ldfw_load.c, there is a possible mitigation bypass due to Permissive Memory Allocation. This cou
In Pixel firmware, there is a possible out of bounds read due to a missing bounds check. This could lead to local inform
Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A
In cd_SsParseMsg of cd_SsCodec.c, there is a possible crash due to a missing null check. This could lead to remote denia
In ConvertUtf8ToUcs2 of radio_hal_utils.cpp, there is a possible out of bounds write due to a missing bounds check. This
In fillSetupDataCallInfo_V1_6 of ril_service_1_6.cpp, there is a possible out of bounds write due to an incorrect bounds
In sms_GetTpUdlIe of sms_PduCodec.c, there is a possible out of bounds read due to a missing bounds check. This could le
In fillSetupDataCallInfo_V1_6 of ril_service_1_6.cpp, there is a possible out of bounds write due to an incorrect bounds
In DoSetCarrierConfig of miscservice.cpp, there is a possible out of bounds read due to an incorrect bounds check. This
In encode of wlandata.cpp, there is a possible out of bounds write due to improper input validation. This could lead to
In ServiceInterface::HandleRequest of serviceinterface.cpp, there is a possible use after free. This could lead to local
In CdmaBroadcastSmsConfigsRequestData::encode of cdmasmsdata.cpp, there is a possible stack clash leading to memory corr
In BroadcastSmsConfigsRequestData::encode of smsdata.cpp, there is a possible out of bounds write due to a missing bound
In MiscService::DoOemSetTcsFci of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check.
In ProtocolSimBuilderLegacy::BuildSimGetGbaAuth of protocolsimbuilderlegacy.cpp, there is a possible out of bounds read
In MiscService::DoOemSetRtpPktlossThreshold of miscservice.cpp, there is a possible out of bounds read due to a missing
In ProtocolImsBuilder::BuildSetConfig of protocolimsbuilder.cpp, there is a possible out of bounds read due to a missing
In ProtocolEmbmsBuilder::BuildSetSession of protocolembmsbuilder.cpp, there is a possible out of bounds write due to a m
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started