Gmail
by Google
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-15464 | Hig | 0.49 | 7.5 | 0.01 | Jan 8, 2026 | Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls. | ||
| CVE-2017-17689 | Med | 0.39 | 5.9 | 0.04 | May 16, 2018 | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. |
- risk 0.49cvss 7.5epss 0.01
Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls.
- risk 0.39cvss 5.9epss 0.04
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.