16,977 known vulnerabilities
Top Products
An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass th
A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrar
Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspanel value in SystemUI
Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_hide_by_meadia_full value in Syst
An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted a
A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial o
An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromis
A possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows arbitra
A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allo
Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to S
In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to loc
In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due
In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIn
In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in othe
In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer ove
In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This
In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead t
In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial o
In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app
In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to u
In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This
In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused d
In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to
In system properties, there is a possible information disclosure due to a missing permission check. This could lead to l
In system properties, there is a possible information disclosure due to a missing permission check. This could lead to l
In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identi
When extracting the incorrectly formatted avi file, the memory is damaged, the playback interface shows that the video c
When extracting the incorrectly formatted flv file, the memory is damaged, the playback interface shows that the video c
In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacki
In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profi
SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within
In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be
In ccu, there is a possible out of bounds read due to incorrect error handling. This could lead to information disclosur
In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege
In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege
In memory management driver, there is a possible memory corruption due to an integer overflow. This could lead to local
In memory management driver, there is a possible side channel information disclosure. This could lead to local informati
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local de
In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to lo
In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local de
In memory management driver, there is a possible information disclosure due to a missing bounds check. This could lead t
In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check.
NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory co
An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows atta
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows atta
NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory co
An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a
OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy
OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitra
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started