16,977 known vulnerabilities
Top Products
In Scudo, there is a possible way for an attacker to predict heap allocation patterns due to insecure implementation/des
In Contacts, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service in th
In ContactsProvider, there is a possible crash loop due to resource exhaustion. This could lead to local persistent deni
In Usage, there is a possible permanent DoS due to resource exhaustion. This could lead to local denial of service with
In Bluetooth, there is a possibility of code-execution due to a use after free. This could lead to paired device escalat
In Bluetooth, there is a possible out of bounds write due to improper input validation. This could lead to local escalat
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal
In libaudioclient, there is a possible out of bounds write due to a use after free. This could lead to local escalation
In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions,
In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disc
In NFA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information discl
In multiple locations, there is a possible background activity launch due to a logic error in the code. This could lead
In Media Projection, there is a possible way to determine whether an app is installed, without query permissions, due to
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to
In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to s
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio
In the Device Idle Controller, there is a possible way to determine whether an app is installed, without query permissio
In Game Manager Service, there is a possible way to determine whether an app is installed, without query permissions, du
In Job Scheduler, there is a possible way to determine whether an app is installed, without query permissions, due to si
In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to lo
In RemoteSpeechRecognitionService of RemoteSpeechRecognitionService.java, there is a possible way to launch an activity
In Permission Manager, there is a possible way to bypass required permissions due to a missing permission check. This co
In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local i
In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could
In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to sid
In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side
In Input Method, there is a possible way to determine whether an app is installed, without query permissions, due to sid
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side ch
In App Ops Service, there is a possible disclosure of information about installed packages due to a logic error in the c
In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to si
In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to si
In InputMethod, there is a possible way to determine whether an app is installed, without query permissions, due to side
In Overlay Manager, there is a possible way to determine whether an app is installed, without query permissions, due to
In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check.
In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due t
In Permission Manager, there is a possible way to determine whether an app is installed, without query permissions, due
In Package Manager Service, there is a possible way to determine whether an app is installed, without query permissions,
In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side ch
In Package Installer, there is a possible way to determine whether an app is installed, without query permissions, due t
In Activity Manager, there is a possible way to determine whether an app is installed, without query permissions, due to
In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lea
In Device Policy, there is a possible way to verify if a particular admin app is registered on the device due to side ch
In UsageStatsService, there is a possible way to read installed 3rd party apps due to side channel information disclosur
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side cha
In ContentService, there is a possible way to determine whether an app is installed, without query permissions, due to s
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side cha
In Bluetooth, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote (proximal/
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started