16,977 known vulnerabilities
Top Products
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information
In Core, there is a possible way to forward calls without user knowledge due to a missing permission check. This could l
In IntentResolver, there is a possible cross-user media read due to a confused deputy. This could lead to local informat
In Settings, there is a possible way to control private DNS settings from a secondary user due to a permissions bypass.
In Bluetooth, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation
In libcore, there is a possible out of bounds read due to a missing bounds check. This could lead to local information d
In Composer, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation o
In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android devi
In ContentService, there is a possible way to read installed sync content providers due to side channel information disc
In Content, there is a possible way to determine whether an app is installed, without query permissions, due to side cha
In Content Service, there is a possible way to determine whether an app is installed, without query permissions, due to
In Content, here is a possible way to determine whether an app is installed, without query permissions, due to side chan
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to
In ActivityManagerService, there is a possible way to determine whether an app is installed, without query permissions,
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to s
In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to
In Slice, there is a possible disclosure of installed applications due to side channel information disclosure. This coul
In SEPolicy, there is a possible way to access the factory MAC address due to a permissions bypass. This could lead to l
In Permission, there is a possible way to determine whether an app is installed, without query permissions, due to side
In SliceManagerService, there is a possible way to check if a content provider is installed due to a missing null check.
In Slice, there is a possible disclosure of installed packages due to a missing permission check. This could lead to loc
In PackageManagerNative, there is a possible way to determine whether an app is installed, without query permissions, du
In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due
In verifyDefaults of CardEmulationManager.java, there is a possible way to set a third party app as the default contactl
In android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code du
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lea
In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lea
In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused depu
In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This
In applyCustomDescription of SaveUi.java, there is a possible way to view another user's images due to a confused deputy
In isFullScreen of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This cou
In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused depu
In GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local es
In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. Th
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could
In several functions of xmlregexp.c, there is a possible out of bounds write due to a heap buffer overflow. This could l
In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local
In onCreate of ApnEditor.java, there is a possible way for a Guest user to change the APN due to a permission bypass. Th
In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused
In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This c
In multiple locations, there is a possible way to bypass user notification of foreground services due to improper input
In resetSettingsLocked of SettingsProvider.java, there is a possible lockscreen bypass due to a permissions bypass. This
In onTaskAppeared of PipTaskOrganizer.java, there is a possible way to bypass background activity launch restrictions du
Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit hea
In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This coul
In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds c
Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a u
Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof securit
Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass aut
Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof se
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started