Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Google

16,977 known vulnerabilities

981
CRITICAL
5,879
HIGH
5,898
MEDIUM
447
LOW

Top Products

android 8109 chrome 4748 tensorflow 431 chrome os 215 asylo 16 blink 12 mcp toolbox for databases 9 linux and chrome os 8 gvisor 7 fuchsia 6
13,206 CVEs · Page 56/265
5.5
CVE-2025-48591

In multiple locations, there is a possible way to read files from another user due to a missing permission check. This c

5.5
CVE-2025-48590

In verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency

7.8
CVE-2025-48589

In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user due

7.8
CVE-2025-48588

In startAlwaysOnVpn of Vpn.java, there is a possible way to disable always-on VPN due to a logic error in the code. This

7.8
CVE-2025-48586

In onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from the work profile due to

5.5
CVE-2025-48584

In multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limi

7.8
CVE-2025-48583

In multiple functions of BaseBundle.java, there is a possible way to execute arbitrary code due to a logic error in the

7.8
CVE-2025-48580

In connectInternal of MediaBrowser.java, there is a possible way to access while in use permission while the app is in b

5.5
CVE-2025-48576

In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanen

7.8
CVE-2025-48575

In multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass

7.8
CVE-2025-48573

In sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service while the app is in

7.8
CVE-2025-48572 KEV

In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. Thi

7.8
CVE-2025-48566

In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input

7.8
CVE-2025-48565

In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the cod

7.0
CVE-2025-48564

In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escala

7.8
CVE-2025-48555

In multiple functions of NotificationStation.java, there is a possible cross-profile information disclosure due to a con

7.8
CVE-2025-48536

In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to mo

7.8
CVE-2025-48525

In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications wh

7.8
CVE-2025-32329

In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the devic

7.8
CVE-2025-32328

In multiple functions of Session.java, there is a possible way to view images belonging to a different user of the devic

6.7
CVE-2025-32319

In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions d

6.7
CVE-2025-22432

In notifyTimeout of CallRedirectionProcessor.java, there is a possible persistent connection due to improper input valid

7.8
CVE-2025-22420

In multiple locations, there is a possible way to leak audio files across user profiles due to a confused deputy. This c

5.0
CVE-2025-14111

A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown pa

4.7
CVE-2025-13992

Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote atta

7.5
CVE-2025-13721

Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via

8.8
CVE-2025-13720

Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer pr

3.5
CVE-2025-13640

Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass aut

8.1
CVE-2025-13639

Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbi

8.8
CVE-2025-13638

Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit

4.3
CVE-2025-13637

Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convince

4.3
CVE-2025-13636

Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinc

4.4
CVE-2025-13635

Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI

4.4
CVE-2025-13634

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to

8.8
CVE-2025-13633

Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromi

5.4
CVE-2025-13632

Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a use

8.8
CVE-2025-13631

Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker

8.8
CVE-2025-13630

Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corru

5.3
CVE-2025-13876

A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is

4.4
CVE-2025-20789

In GPU pdma, there is a possible information disclosure due to a missing bounds check. This could lead to local informat

4.4
CVE-2025-20788

In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lead to local denial of

6.7
CVE-2025-20777

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

6.7
CVE-2025-20776

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of

6.7
CVE-2025-20775

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20774

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

6.7
CVE-2025-20773

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20772

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20771

In display, there is a possible escalation of privilege due to improper input validation. This could lead to local escal

6.7
CVE-2025-20770

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20769

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

Frequently Asked Questions

How many CVEs affect Google?

Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Google vulnerabilities?

Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Google vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Google Vulnerabilities

CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.

Get Started