16,977 known vulnerabilities
Top Products
In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a
In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could
In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to imp
In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission che
Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corr
In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of pr
In vpu, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi
In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to loca
In camera middleware, there is a possible out of bounds write due to a missing input validation. This could lead to loca
In rpmb , there is a possible double free due to improper locking. This could lead to local escalation of privilege with
In rpmb , there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of pr
In ftm, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In video, there is a possible out of bounds write due to a permissions bypass. This could lead to local escalation of pr
In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denia
In display, there is a possible information disclosure due to a missing bounds check. This could lead to local informati
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remo
Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to instal
Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to e
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that
The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back
he vulnerability is to delete arbitrary files in LGInstallService ("com.lge.lginstallservies") app. The app contains the
he vulnerability is that the Call management ("com.android.server.telecom") app patched by LG launches implicit intents
The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned i
The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft
The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamer
The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/
The vulnerability is to theft of arbitrary files with system privilege in the LockScreenSettings ("com.lge.lockscreenset
The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notificati
NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on
Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfus
Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to
Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to
Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof secur
Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass
Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote a
Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof securit
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to
In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to an integer overflow. This could lead to
In bindSelection of DatabaseUtils.java, there is a possible way to access files from other applications due to SQL injec
In hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary components due to a
In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. Thi
In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. Thi
In MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead
In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission c
In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity la
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started