Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Google

16,977 known vulnerabilities

981
CRITICAL
5,879
HIGH
5,898
MEDIUM
447
LOW

Top Products

android 8109 chrome 4748 tensorflow 431 chrome os 215 asylo 16 blink 12 mcp toolbox for databases 9 linux and chrome os 8 gvisor 7 fuchsia 6
13,206 CVEs · Page 59/265
6.5
CVE-2025-55556

TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in t

8.8
CVE-2025-10892

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co

8.8
CVE-2025-10891

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co

9.1
CVE-2025-10890

Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-

9.8
CVE-2025-10585 KEV

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corr

8.8
CVE-2025-10502

Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit

8.8
CVE-2025-10501

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap

8.8
CVE-2025-10500

Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap co

8.8
CVE-2025-10201

Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remo

8.8
CVE-2025-10200

Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potenti

7.8
CVE-2025-32320

In System UI, there is a possible way to view other users' images due to a confused deputy. This could lead to local esc

8.8
CVE-2025-32318

In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of

5.5
CVE-2025-32317

In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead to local information

5.5
CVE-2025-32316

In gralloc4, there is a possible out of bounds write due to a missing bounds check. This could lead to local information

3.3
CVE-2025-26461

In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the u

5.5
CVE-2025-26434

In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclo

5.5
CVE-2024-0028

In Audio Service, there is a possible way to obtain MAC addresses of nearby Bluetooth devices due to a missing permissio

7.8
CVE-2025-32322

In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enablin

7.8
CVE-2025-26439

In getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to b

7.8
CVE-2025-26431

In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility se

3.3
CVE-2025-26419

In initPhoneSwitch of SystemSettingsFragment.java, there is a possible FRP bypass due to a logic error in the code. This

4.0
CVE-2025-22415

In android_app of Android.bp, there is a possible way to launch any activity as a system user. This could lead to local

7.8
CVE-2025-22414

In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permiss

4.0
CVE-2024-49731

In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new

6.2
CVE-2024-40664

In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility s

8.4
CVE-2025-48581

In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the

7.8
CVE-2025-48563

In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default va

5.0
CVE-2025-48562

In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could

5.5
CVE-2025-48561

In multiple locations, there is a possible way to access data displayed on the screen due to side channel information di

5.5
CVE-2025-48560

In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confused deputy. This could

5.5
CVE-2025-48559

In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input val

7.8
CVE-2025-48558

In multiple functions of BatteryService.java, there is a possible way to hijack implicit intent intended for system app

7.3
CVE-2025-48556

In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper

6.1
CVE-2025-48554

In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a l

7.8
CVE-2025-48553

In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device admin due to a logic er

7.8
CVE-2025-48552

In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from persistence due to a

5.0
CVE-2025-48551

In multiple locations, there is a possible leak of an image across the Android User isolation boundary due to a confused

5.5
CVE-2025-48550

In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path trav

7.8
CVE-2025-48549

In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. T

7.3
CVE-2025-48548

In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the priva

7.3
CVE-2025-48547

In multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead

7.8
CVE-2025-48546

In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in

7.1
CVE-2025-48545

In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a conf

7.8
CVE-2025-48544

In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could le

8.8
CVE-2025-48543 KEV

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use aft

5.5
CVE-2025-48542

In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exh

7.8
CVE-2025-48541

In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to imprope

7.8
CVE-2025-48540

In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the co

8.0
CVE-2025-48539

In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead t

5.5
CVE-2025-48538

In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical pa

Frequently Asked Questions

How many CVEs affect Google?

Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Google vulnerabilities?

Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Google vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Google Vulnerabilities

CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.

Get Started