Google Authenticator
- Known vulnerabilities
- 0
- Still open
- 0
- KEV open
- 0
- Max CVSS (historical)
- —
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +0/+10
0 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Based on permissions only: no CVE data referenced for this app.
Known vulnerabilities (CVE)
No CVE is currently referenced in NVD for this app on its platform.
The absence of CVEs is not a security guarantee — it can also mean nobody has audited or published findings.
Context
Context
Description
Google Authenticator adds an extra layer of security to your online accounts by adding a second step of verification when you sign in. This means that in addition to your password, you'll also need to enter a code that is generated by the Google Authenticator app on your phone. The verification code can be generated by the Google Authenticator app on your phone, even if you don't have a network or cellular connection. • Sync your Authenticator codes to your Google Account and across your devices. This way, you can always access them even if you lose your phone. • Set up your Authenticator accounts automatically with a QR code. This is quick and easy, and it helps to ensure that your codes are set up correctly. • Support for multiple accounts. You can use the Authenticator app to manage multiple accounts, so you don't have to switch between apps every time you need to sign in. • Support for time-based and counter-based code generation. You can choose the type of code generation that best suits your needs. • Transfer accounts between devices with a QR code. This is a convenient way to move your accounts to a new device.
Data collected and shared
Source: App Store · App Privacy · 8 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
Other apps by this publisher
Apps published by Google LLC
com.google.android.projection.gearheadcom.google.android.apps.work.clouddpccom.google.android.apps.restorecom.google.android.ascom.google.android.safetycorecom.google.android.webviewFAQ
FAQ: Google Authenticator
Why are no CVEs listed for Google Authenticator?
No CVE is currently referenced in NVD for Google Authenticator (com.google.Authenticator) with a iOS CPE configuration. Either none has been publicly disclosed, or none has been mapped yet. Absence of a CVE is not a security guarantee.
What is the latest known version of Google Authenticator?
The most recent version of Google Authenticator (com.google.Authenticator) tracked by Appaloosa Scout is 5.0.2, published by Google LLC.