16,977 known vulnerabilities
Top Products
In multiple locations, there is a possible notification listener grant to an app running in the work profile due to a lo
In TBD of TBD, there is a possible confusion of OEM and DRM certificates due to improperly used crypto. This could lead
In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. Thi
In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion.
In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error.
In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due
In multiple functions of CompanionDeviceManagerService.java, there is a possible launch NotificationAccessConfirmationAc
Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially explo
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap c
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local esca
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation
In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local esc
In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio
In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of pr
The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a st
This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint th
Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap co
Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially e
Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap cor
Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data v
Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap co
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corru
Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass con
Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced
Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mix
Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform
Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform U
Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to in
Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to b
Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sens
Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a use
Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the rendere
Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit hea
Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploi
Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object
Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit
Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap co
Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had co
In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service wi
In faceid service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial
In vsp driver, there is a possible missing verification incorrect input. This could lead to local denial of service with
In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of ser
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote
In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service wit
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started