16,977 known vulnerabilities
Top Products
In pb_write of pb_encode.c, there is a possible out of bounds write due to a missing bounds check. This could lead to lo
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to an integer overflow. This could lead t
In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation
In ImportVCardActivity, there is a possible way to bypass user consent due to a tapjacking/overlay attack. This could le
In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to loca
In onActivityResult of QuickContactActivity.java, there is an unnecessary return of an intent. This could lead to local
In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly saved screenshot due to
In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a us
In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible out of bounds write d
In several functions of InputDispatcher.cpp, WindowManagerService.java, and related files, there is a possible tapjackin
In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds read due to integer overflow. This could
In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could
In onCreate of DeviceChooserActivity.java, there is a possible way to bypass user consent when pairing a Bluetooth devic
In ClearPullerCacheIfNecessary and ForceClearPullerCache of StatsPullerManager.cpp, there is a possible use-after-free d
In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could
In pollOnce of ALooper.cpp, there is possible memory corruption due to a use after free. This could lead to local escala
In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing
In parseExclusiveStateAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow.
In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer ove
In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of
Use after free in Aura in Google Chrome on Linux prior to 89.0.4389.114 allowed a remote attacker who had compromised th
Out of bounds read in IPC in Google Chrome prior to 89.0.4389.114 allowed a remote attacker who had compromised the rend
Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploi
Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389.114 allowed a remote attacker to potenti
Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corru
Use after free in screen sharing in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploi
Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android
Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in
Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9
An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the
A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged application
An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to ac
An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to dele
An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read
An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers
An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without prope
A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to ac
A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.
An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged appli
An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can leverage ISMS servic
An issue was discovered on LG mobile devices with Android OS 11 software. Attackers can bypass the lockscreen protection
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0
Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physical
Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to
Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action wi
Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap cor
Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially explo
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started