16,977 known vulnerabilities
Top Products
Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13
In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow.
In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications i
In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps
In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local
In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due
In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired d
In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the
In canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most common
In multiple locations, there is a possible method for a malicious app to prevent dialing emergency services under limite
In isInSignificantPlace of multiple files, there is a possible way to access sensitive information due to a missing perm
In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could le
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on t
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above t
In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This coul
In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app whe
In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification content leak throug
In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to
In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation o
In finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacki
In onCreate of ChooserActivity.java , there is a possible way to view other users' images due to a confused deputy. This
In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation
In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible cross user media disclosure due to a confused
In showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy.
In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissi
In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the ba
In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil
In mbrain, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege
In monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of pri
A vulnerability was identified in GalleryVault Gallery Vault App up to 4.5.2 on Android. Affected by this issue is some
A security flaw has been discovered in Modo Legend of the Phoenix up to 1.0.5. The affected element is an unknown functi
A vulnerability was determined in Voice Changer App up to 1.1.0. This issue affects some unknown processing of the file
A flaw has been found in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functio
In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening fil
In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This cou
In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could
In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. Th
In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc
In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This
In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This c
In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. Th
In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free.
In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc
In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This
In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after
In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission
In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficien
In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission c
In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code e
In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This c
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started