Google Google Software and search

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Google product.

RSS Feeds for Google security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Google products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Google Sorted by Most Security Vulnerabilities since 2018

Google Android6556 vulnerabilities
Mobile operating system

Google Chrome6502 vulnerabilities
Web browser

Google Tensorflow432 vulnerabilities
Open source machine learning / AI library

Google ChromeOS51 vulnerabilities

Google Asylo16 vulnerabilities

Google Protobuf8 vulnerabilities

Google Gvisor7 vulnerabilities

Google Fuchsia5 vulnerabilities

Google Gerrit5 vulnerabilities

Google Protobuf Java5 vulnerabilities

Google Protobuf Javalite4 vulnerabilities

Google Web Toolkit3 vulnerabilities

Google Protobuf Kotlin3 vulnerabilities

Google Web Stories3 vulnerabilities

Google Web Designer3 vulnerabilities

Google Chromecast Firmware2 vulnerabilities

Google Firebase Php Jwt2 vulnerabilities

Google Nearby2 vulnerabilities

Google Protobuf Kotlin Lite2 vulnerabilities

Google Protobuf Python2 vulnerabilities

Google Updater2 vulnerabilities

Google Androidx Car App1 vulnerability

Google Bazel For Clion1 vulnerability

Google Bazel For Intellij1 vulnerability

Google Car1 vulnerability

Google Cloud Looker1 vulnerability

Google Drive1 vulnerability

Google Secops Soar1 vulnerability

Google Site Kit1 vulnerability

Google Looker1 vulnerability

Google Nftables1 vulnerability

Google Pixel1 vulnerability

Google Quick Share1 vulnerability

Google Reverb1 vulnerability

Google Safearchive1 vulnerability

Google Tensorflow Serving1 vulnerability

Google Tink C1 vulnerability

Google Vertex Ai1 vulnerability

Recent Google Security Advisories

Advisory Title Published
2026-09-16 Chrome Releases: Chrome for Android Update (version 153) September 16, 2026
2026-09-15 Chrome Releases: Chrome Stable for iOS Update (version 154) September 15, 2026
2026-09-15 Chrome Releases: Stable Channel Update for Desktop (version 153.0.8010.47) September 15, 2026
2026-09-08 Chrome Releases: Stable Channel Update for ChromeOS / ChromeOS Flex September 8, 2026
2026-09-08 Chrome Releases: Stable Channel Update for Desktop (version 153) September 8, 2026
2026-09-08 Chrome Releases: Chrome for Android Update (version 153) September 8, 2026
2026-09-04 Chrome Releases: Chrome for Android Update (version 152) September 4, 2026
2026-09-03 Chrome Releases: Stable Channel Update for Desktop (version 152.0.7977.82) September 3, 2026
2026-09-02 Chrome Releases: September 2026 September 2, 2026
2026-09-02 Chrome Releases: Chrome Stable for iOS Update (version 153) September 2, 2026

Known Exploited Google Vulnerabilities

The following Google vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Google Chromium V8 Out of Bounds Write Vulnerability Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-87491
September 9, 2026
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-85046
September 4, 2026
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-11645 Exploit Probability: 2.2%
June 9, 2026
Google Dawn Use-After-Free Vulnerability Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-5281 Exploit Probability: 5.5%
April 1, 2026
Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerabi Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-3910 Exploit Probability: 2.0%
March 13, 2026
Google Skia Out-of-Bounds Write Vulnerability Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
CVE-2026-3909 Exploit Probability: 1.6%
March 13, 2026
Google Chromium CSS Use-After-Free Vulnerability Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-2441 Exploit Probability: 22.0%
February 17, 2026
Google Chromium Out of Bounds Memory Access Vulnerability Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2025-14174 Exploit Probability: 22.7%
December 12, 2025
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.
CVE-2025-13223 Exploit Probability: 4.9%
November 19, 2025
Google Chromium V8 Type Confusion Vulnerability Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine.
CVE-2025-10585 Exploit Probability: 5.4%
September 23, 2025
Google Chromium ANGLE and GPU Improper Input Validation Vulnerability Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2025-6558 Exploit Probability: 9.0%
July 22, 2025
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2025-6554 Exploit Probability: 8.6%
July 2, 2025
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2025-5419 Exploit Probability: 6.5%
June 5, 2025
Google Chromium Loader Insufficient Policy Enforcement Vulnerability Google Chromium contains an insufficient policy enforcement vulnerability that allows a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2025-4664 Exploit Probability: 5.4%
May 15, 2025
Google Chromium Mojo Sandbox Escape Vulnerability Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2025-2783 Exploit Probability: 8.4%
March 27, 2025
Google Chromium V8 Inappropriate Implementation Vulnerability Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2024-7965 Exploit Probability: 18.4%
August 28, 2024
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2024-7971 Exploit Probability: 20.5%
August 26, 2024
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2024-5274 Exploit Probability: 10.0%
May 28, 2024
Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.
CVE-2024-4947 Exploit Probability: 15.1%
May 20, 2024
Google Chromium V8 Out-of-Bounds Memory Write Vulnerability Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2024-4761 Exploit Probability: 11.0%
May 16, 2024

7 known exploited Google vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

Top 10 Riskiest Google Vulnerabilities

Based on the current exploit probability, these Google vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.

Rank CVE EPSS Vulnerability
1 CVE-2023-4863 100.0% Google Chromium Heap-Based Buffer Overflow Vulnerability
2 CVE-2018-17463 84.6% Google Chromium V8 Remote Code Execution Vulnerability
3 CVE-2021-21224 84.2% Chromium V8 JavaScript Engine Remote Code Execution Vulnerability
4 CVE-2020-6418 78.8% Chromium V8 Type Confusion Vulnerability
5 CVE-2019-13720 73.0% Google Chrome Use-After-Free Vulnerability
6 CVE-2021-21220 70.4% Chromium V8 Input Validation Vulnerability
7 CVE-2021-30551 64.7% Chromium V8 Type Confusion Vulnerability
8 CVE-2021-30632 63.2% Google Chrome Out-of-bounds write
9 CVE-2019-5786 61.5% Google Chrome Use-After-Free Vulnerability
10 CVE-2018-6065 60.3% Google Chromium V8 Integer Overflow Vulnerability

By the Year

In 2026 there have been 3403 vulnerabilities in Google with an average score of 7.0 out of ten. Last year, in 2025 Google had 720 security vulnerabilities published. That is, 2683 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.13




Year Vulnerabilities Average Score
2026 3403 7.04
2025 720 7.17
2024 1125 7.29
2023 1564 6.66
2022 1592 6.85
2021 1166 7.11
2020 1033 6.87
2019 858 7.33
2018 570 7.43

It may take a day or so for new Google vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Google Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-91738 Sep 15, 2026
Google Chrome ANGLE Improper Input Validation (pre-153.0.8010.47) Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-91730 Sep 15, 2026
Chrome GetUserMedia Cleanup Flaw (v<153.0.8010.47) Enables Cross-Origin Leak Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-91722 Sep 15, 2026
Use-after-free in Chrome <153.0.8010.47 Input component Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-91719 Sep 15, 2026
Chrome XML Injection <=153.0.8010.46 Bypass Origin Policy Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Chrome
CVE-2026-91713 Sep 15, 2026
Missing Auth in Chrome <153.0.8010.47: UI Spoof via Renderer Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-91742 Sep 15, 2026
Confused Deputy in Chrome PriceTracking iOS <153.0.8010.47 Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium)
Chrome
CVE-2026-91739 Sep 15, 2026
Chrome <153.0.8010.47: Auth Gap in Transactions Platform Allows Renderer Spoof Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-91725 Sep 15, 2026
Chrome CSS Disclosure Before 153.0.8010.47 Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-91714 Sep 15, 2026
Format Data Leak via Font Mismatch in Chrome (<153.0.8010.47) Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-91745 Sep 15, 2026
Use-After-Free in V8 (Chrome <153.0.8010.47) Allows RCE Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91732 Sep 15, 2026
Missing Auth in Chrome AppManifest (<=153.0.8010.47) Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-91723 Sep 15, 2026
Chrome <153.0.8010.47 WebAppInstalls Race Condition UI Spoofing Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Chrome
CVE-2026-91715 Sep 15, 2026
Google Chrome ServiceWorker Type Confusion < 153.0.8010.47 RCE Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91711 Sep 15, 2026
Out-of-bounds write in Chrome ServiceWorker (pre-153.0.8010.47) Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91746 Sep 15, 2026
Google Chrome <153.0.8010.47 Int Overflow in Compositing Allows X-OR Data Leak Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91737 Sep 15, 2026
Use-after-free in Chrome PDF before 153.0.8010.47 allows sandbox escape Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91729 Sep 15, 2026
Use-after-free in Chrome DigitalCredentials (pre-153.0.8010.47) Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91716 Sep 15, 2026
UAF in Auth prior to 153.0.8010.47 in Google Chrome Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91740 Sep 15, 2026
Uninitialized Skia res. in Chrome <153.0.8010.47 allows remote XOR leak Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91736 Sep 15, 2026
Chrome UAF in DOM before 153.0.8010.47 (remote code exec) Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91718 Sep 15, 2026
UAoF in Chrome Core before 153.0.8010.47 enables remote code exec Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91710 Sep 15, 2026
UA-FREE Chrome WebAppInstalls <153.0.8010.47: Remote Code Exec Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91741 Sep 15, 2026
Type Confusion in CacheStorage in Chrome <153.0.8010.47 Enables Remote Code Execution Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91735 Sep 15, 2026
Google Chrome 153.0.8010.47 WebUI Wrong Auth Arbitrary Code Exec Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91717 Sep 15, 2026
Missing Auth in Google Chrome Android <153.0.8010.47 via Co-installed App Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)
Chrome
CVE-2026-91709 Sep 15, 2026
ServiceWorker Type Confusion in Chrome <153.0.8010.47 (Arbitrary Code Exec) Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91708 Sep 15, 2026
Chrome <153.0.8010.47 Race Cond. in Network Allows CO Data Leak Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91747 Sep 15, 2026
Use-After-Free in Skia of Chrome <153.0.8010.47 via crafted HTML Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91733 Sep 15, 2026
Chrome Skia Remote Memory Leak via Improper State Validation (Fixed 153.0.8010.47) Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91731 Sep 15, 2026
Chrome 153.0.8010.47 Type Confusion in Compositing (Remote Code Exec) Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91720 Sep 15, 2026
Uninitialized Resource in ANGLE -> Remote Memory Disclosure in Chrome<153 Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91748 Sep 15, 2026
Google Chrome MAC <153.0.8010.47 Race Condition in Extensions Escalates RCE Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
Chrome
CVE-2026-91744 Sep 15, 2026
Race Condition in Chrome (<153.0.8010.47) Enables Remote Info Leak Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91712 Sep 15, 2026
CVE-2026-91712: Chrome Mac Race Condition RCE before 153.0.8010.47 Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91743 Sep 15, 2026
Chrome <153.0.8010.47 Race Condition: Remote Code Execution via Crafted HTML Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91734 Sep 15, 2026
Chrome Windows <153.0.8010.47 Local Auth Bypass Exec Outside Sandbox Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Chrome
CVE-2026-91727 Sep 15, 2026
Chrome Mac <153.0.8010.47 Extension Ref Resolved Exec Outside Sandbox Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Chrome
CVE-2026-91749 Sep 15, 2026
Use-After-Free in Chrome Workers before 153.0.8010.47 Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Chrome
CVE-2026-91728 Sep 15, 2026
Integer overflow in V8 (Chrome <153.0.8010.47) allows remote code exec Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91724 Sep 15, 2026
Google Chrome <153.0.8010.47: Input USEAFTERFREE in renderer Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
CVE-2026-91726 Sep 15, 2026
Chrome Android WebGL OOB read <153.0.8010.47 Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Chrome
CVE-2026-91721 Sep 15, 2026
UAF in Chrome Internals before 153.0.8010.47 Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Chrome
CVE-2026-58773 Sep 15, 2026
In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2026-58767 Sep 15, 2026
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2026-58766 Sep 15, 2026
In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2026-58765 Sep 15, 2026
In GPU, there is a possible permission bypass due to a logic error in the code In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2026-58755 Sep 15, 2026
In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2026-58751 Sep 15, 2026
In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2026-58747 Sep 15, 2026
In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2026-58744 Sep 15, 2026
In multiple locations, there is a possible escalation of privilege due to improper input validation In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.