16,977 known vulnerabilities
Top Products
In Keyguard, there is a missing permission check. This could lead to local escalation of privilege and prevention of scr
In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote informatio
In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to
In PermissionController, there is a possible way to grant some permissions without user consent due to misleading or ins
In Content, there is a possible way to learn gmail account name on the device due to a permissions bypass. This could le
In Bluetooth, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalat
In RestrictionsManager, there is a possible way to send a broadcast that should be restricted to system apps due to a pe
In bluetooth, there is a possible way to enable or disable bluetooth connection without user consent due to a missing pe
In Companion, there is a possible way to keep a service running with elevated importance without showing foreground serv
In Settings, there is a possible way to bypass factory reset permissions due to a permissions bypass. This could lead to
In ActivityManager, there is a way to read process state for other users due to a missing permission check. This could l
In ActivityManager, there is a possible way to check another process's capabilities due to a missing permission check. T
In LocationManager, there is a possible way to get location information due to a missing permission check. This could le
In the Phone app, there is a possible crash loop due to resource exhaustion. This could lead to local persistent denial
In Telephony, there is a possible leak of ICCID and EID due to a missing permission check. This could lead to local info
In Bluetooth, there is a possible way to bypass compiler exploit mitigations due to a configuration error. This could le
In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the
In the Audio HAL, there is a possible out of bounds write due to a race condition. This could lead to local escalation o
In SettingsProvider, there is a possible way to read or change the default ringtone due to a missing permission check. T
In Wi-Fi, there is a permissions bypass. This could lead to local escalation of privilege from the guest user with no ad
In Bluetooth, there is a possible cleanup failure due to an uncaught exception. This could lead to remote denial of serv
Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed
Product: AndroidVersions: Android kernelAndroid ID: A-204782372References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-210916981References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-184676385References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-205714161References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A
In SAEMM_RetrievEPLMNList of SAEMM_ContextManagement.c, there is a possible out of bounds read due to a missing bounds c
In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check. This could lead to r
Product: AndroidVersions: Android kernelAndroid ID: A-211727306References: N/A
In AllocateInternalBuffers of g3aa_buffer_allocator.cc, there is a possible out of bounds write due to an integer overfl
In (TBD) of (TBD), there is a possible out of bounds write due to kernel stack overflow. This could lead to local escala
Product: AndroidVersions: Android kernelAndroid ID: A-188935887References: N/A
Product: AndroidVersions: Android kernelAndroid ID: A-212625740References: N/A
In lwis_buffer_alloc of lwis_buffer.c, there is a possible arbitrary code execution due to a use after free. This could
Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A
In TBD of keymaster_ipc.cpp, there is a possible to force gatekeeper, fingerprint, and faceauth to use a known HMAC key.
In trusty_log_seq_start of trusty-log.c, there is a possible use after free due to improper locking. This could lead to
In LteRrcNrProAsnDecode of LteRrcNr_Codec.c, there is a possible out of bounds read due to a missing bounds check. This
In st21nfc_loc_set_polaritymode of fc/st21nfc.c, there is a possible use after free due to a race condition. This could
In exynos5_i2c_irq of (TBD), there is a possible out of bounds write due to a use after free. This could lead to local e
In dm_bow_dtr and related functions of dm-bow.c, there is a possible use after free due to a race condition. This could
Product: AndroidVersions: Android kernelAndroid ID: A-215730643References: N/A
In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This c
Product: AndroidVersions: Android kernelAndroid ID: A-224546354References: Upstream kernel
In construct_transaction of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could
In ioctl_dpm_clk_update of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could
Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started