16,977 known vulnerabilities
Top Products
In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege
In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities
In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a lo
In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This coul
In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a devic
In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to
In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user c
In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected
In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This cou
In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This co
In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This cou
In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This coul
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could
In multiple locations, there is a possible way to obtain any system permission due to a logic error in the code. This co
In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in
In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permiss
In multiple locations, there is a possible way to access media content belonging to another user due to a missing permis
In multiple locations, there is a possible way to read protected files due to a missing permission check. This could lea
In onAttachFragment of ShareIntentActivity.java, there is a possible way for an app to read files in the messages app du
In NlpService, there is a possible way to obtain location information due to a missing permission check. This could lead
In BnDmAgent::onTransact of dm_agent.cpp, there is a possible out of bounds write due to a missing bounds check. This co
In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This
In ip6_append_data of ip6_output.c, there is a possible way to achieve code execution due to a heap buffer overflow. Thi
In multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an integer overflow. This c
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to
In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could le
In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local in
In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could
In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profil
In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a c
In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictio
In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services d
Inappropriate implementation in Compositing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform
Inappropriate implementation in Navigation in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform
Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinc
Insufficient data validation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinc
Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced
Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtai
Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker
Race in Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in speci
Stack buffer overflow in Tracing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploi
Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit h
Integer overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap c
Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker
Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially explo
Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside
In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This
When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote
In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started