16,977 known vulnerabilities
Top Products
Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to insta
Heap buffer overflow in Tab Groups in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to i
Use after free in File Manager in Google Chrome on Chrome OS prior to 98.0.4758.102 allowed a remote attacker to potenti
In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to l
In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions,
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could
In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local esca
In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the dev
In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation
In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission chec
In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local es
In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This
In SmsController, there is a possible information disclosure due to a permissions bypass. This could lead to local escal
In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing p
In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local informatio
In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to imprope
In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a miss
In NFC, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege
In People, there is a possible way to determine whether an app is installed, without query permissions, due to side chan
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of s
In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosur
In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check. This co
In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validat
In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could l
In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a
In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing per
In miniadb, there is a possible way to get read/write access to recovery system properties due to an insecure default va
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side ch
In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclos
In Settings, there is a possible way to display an incorrect app name due to improper input validation. This could lead
In Settings, there is a possible way to make the user enable WiFi due to improper input validation. This could lead to l
In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to remote information dis
In Media, there is a possible way to determine whether an app is installed, without query permissions, due to side chann
In AudioService, there is a possible way to determine whether an app is installed, without query permissions, due to sid
In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to local escalati
In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission
In PermissionController, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local
In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side c
In DevicePolicyManager, there is a possible way to reveal the existence of an installed package without proper query per
In ContextImpl, there is a possible way to determine whether an app is installed, without query permissions, due to side
In DomainVerificationService, there is a possible way to access app domain verification information due to a missing per
In Bubbles, there is a possible way to interfere with Bubbles due to a permissions bypass. This could lead to local esca
In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permissi
In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission c
In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission che
In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent
In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass
In PermissionController, there is a possible way to delete some local files due to an unsafe PendingIntent. This could l
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started