16,977 known vulnerabilities
Top Products
In multiple locations, there is a possible way to read files from another user due to a missing permission check. This c
In verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency
In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user due
In startAlwaysOnVpn of Vpn.java, there is a possible way to disable always-on VPN due to a logic error in the code. This
In onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from the work profile due to
In multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limi
In multiple functions of BaseBundle.java, there is a possible way to execute arbitrary code due to a logic error in the
In connectInternal of MediaBrowser.java, there is a possible way to access while in use permission while the app is in b
In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanen
In multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass
In sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service while the app is in
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. Thi
In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input
In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the cod
In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escala
In multiple functions of NotificationStation.java, there is a possible cross-profile information disclosure due to a con
In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to mo
In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications wh
In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the devic
In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the devic
In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions d
In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input valid
In multiple locations, there is a possible way to leak audio files across user profiles due to a confused deputy. This c
A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown pa
Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote atta
Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via
Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer pr
Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass aut
Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbi
Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit
Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convince
Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinc
Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to
Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromi
Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a use
Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker
Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corru
A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is
In GPU pdma, there is a possible information disclosure due to a missing bounds check. This could lead to local informat
In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lead to local denial of
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible escalation of privilege due to improper input validation. This could lead to local escal
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started