Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Google

16,977 known vulnerabilities

981
CRITICAL
5,879
HIGH
5,898
MEDIUM
447
LOW

Top Products

android 8109 chrome 4748 tensorflow 431 chrome os 215 asylo 16 blink 12 mcp toolbox for databases 9 linux and chrome os 8 gvisor 7 fuchsia 6
13,206 CVEs · Page 151/265
8.8
CVE-2022-0605

Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to insta

8.8
CVE-2022-0604

Heap buffer overflow in Tab Groups in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to i

8.8
CVE-2022-0603

Use after free in File Manager in Google Chrome on Chrome OS prior to 98.0.4758.102 allowed a remote attacker to potenti

7.8
CVE-2022-20002

In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to l

5.5
CVE-2021-39791

In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions,

7.8
CVE-2021-39790

In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could

7.8
CVE-2021-39789

In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local esca

5.5
CVE-2021-39788

In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the dev

7.8
CVE-2021-39787

In SystemUI, there is a possible arbitrary Activity launch due to a confused deputy. This could lead to local escalation

6.7
CVE-2021-39786

In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

7.8
CVE-2021-39784

In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission chec

7.8
CVE-2021-39783

In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local es

7.8
CVE-2021-39782

In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This

7.8
CVE-2021-39781

In SmsController, there is a possible information disclosure due to a permissions bypass. This could lead to local escal

7.8
CVE-2021-39780

In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing p

5.5
CVE-2021-39779

In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local informatio

5.5
CVE-2021-39778

In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to imprope

5.5
CVE-2021-39777

In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a miss

7.8
CVE-2021-39776

In NFC, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege

5.5
CVE-2021-39775

In People, there is a possible way to determine whether an app is installed, without query permissions, due to side chan

5.5
CVE-2021-39774

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of s

5.5
CVE-2021-39773

In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosur

8.8
CVE-2021-39772

In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check. This co

7.8
CVE-2021-39771

In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validat

5.5
CVE-2021-39770

In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could l

5.5
CVE-2021-39769

In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a

7.8
CVE-2021-39768

In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing per

7.8
CVE-2021-39767

In miniadb, there is a possible way to get read/write access to recovery system properties due to an insecure default va

5.5
CVE-2021-39766

In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side ch

5.5
CVE-2021-39765

In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclos

7.8
CVE-2021-39764

In Settings, there is a possible way to display an incorrect app name due to improper input validation. This could lead

7.8
CVE-2021-39763

In Settings, there is a possible way to make the user enable WiFi due to improper input validation. This could lead to l

7.5
CVE-2021-39762

In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to remote information dis

5.5
CVE-2021-39761

In Media, there is a possible way to determine whether an app is installed, without query permissions, due to side chann

5.5
CVE-2021-39760

In AudioService, there is a possible way to determine whether an app is installed, without query permissions, due to sid

7.8
CVE-2021-39759

In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to local escalati

7.8
CVE-2021-39758

In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission

5.5
CVE-2021-39757

In PermissionController, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local

5.5
CVE-2021-39756

In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side c

5.5
CVE-2021-39755

In DevicePolicyManager, there is a possible way to reveal the existence of an installed package without proper query per

5.5
CVE-2021-39754

In ContextImpl, there is a possible way to determine whether an app is installed, without query permissions, due to side

5.5
CVE-2021-39753

In DomainVerificationService, there is a possible way to access app domain verification information due to a missing per

7.8
CVE-2021-39752

In Bubbles, there is a possible way to interfere with Bubbles due to a permissions bypass. This could lead to local esca

5.5
CVE-2021-39751

In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permissi

7.8
CVE-2021-39750

In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission c

7.8
CVE-2021-39749

In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission che

5.5
CVE-2021-39748

In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent

5.5
CVE-2021-39747

In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass

7.8
CVE-2021-39746

In PermissionController, there is a possible way to delete some local files due to an unsafe PendingIntent. This could l

5.5
CVE-2021-39745

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due

Frequently Asked Questions

How many CVEs affect Google?

Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Google vulnerabilities?

Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Google vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Google Vulnerabilities

CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.

Get Started