16,977 known vulnerabilities
Top Products
TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in t
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co
Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corr
Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit
Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap
Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap co
Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remo
Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potenti
In System UI, there is a possible way to view other users' images due to a confused deputy. This could lead to local esc
In Skia, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of
In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead to local information
In gralloc4, there is a possible out of bounds write due to a missing bounds check. This could lead to local information
In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the u
In libxml2, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclo
In Audio Service, there is a possible way to obtain MAC addresses of nearby Bluetooth devices due to a missing permissio
In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a malicious app a token enablin
In getComponentName of AccessibilitySettingsUtils.java, there is a possible way to for a malicious Talkback service to b
In setupAccessibilityServices of AccessibilityFragment.java, there is a possible way to hide an enabled accessibility se
In initPhoneSwitch of SystemSettingsFragment.java, there is a possible FRP bypass due to a logic error in the code. This
In android_app of Android.bp, there is a possible way to launch any activity as a system user. This could lead to local
In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP due to a missing permiss
In apk-versions.txt, there is a possible corruption of telemetry opt-in settings on other watches when setting up a new
In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility s
In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates due to a logic error in the
In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default va
In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could
In multiple locations, there is a possible way to access data displayed on the screen due to side channel information di
In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confused deputy. This could
In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops due to improper input val
In multiple functions of BatteryService.java, there is a possible way to hijack implicit intent intended for system app
In multiple methods of NotificationChannel.java, there is a possible desynchronization from persistence due to improper
In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a l
In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device admin due to a logic er
In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync from persistence due to a
In multiple locations, there is a possible leak of an image across the Android User isolation boundary due to a confused
In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path trav
In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. T
In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the priva
In multiple locations, there is a possible one-time permission bypass due to a logic error in the code. This could lead
In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in
In isSystemUid of AccountManagerService.java, there is a possible way for an app to access privileged APIs due to a conf
In multiple locations, there is a possible way to read files belonging to other apps due to SQL injection. This could le
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use aft
In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exh
In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user profiles due to imprope
In processTransactInternal of RpcState.cpp, there is a possible local out of memory write due to a logic error in the co
In SendPacketToPeer of acl_arbiter.cc, there is a possible out of bounds read due to a use after free. This could lead t
In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to hide a system critical pa
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started