Google Software and search
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Google product.
RSS Feeds for Google security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Google products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Google Sorted by Most Security Vulnerabilities since 2018
Recent Google Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 2026-07-22 | Chrome Releases: Chrome Stable for iOS Update (version 151) | July 22, 2026 |
| 2026-07-22 | Chrome Releases: Stable Channel Update for Desktop (version 150.0.7871.181) | July 22, 2026 |
| 2026-07-22 | Chrome Releases: Chrome for Android Update (version 150) | July 22, 2026 |
| 2026-07-17 | Chrome Releases: Stable Channel Update for Desktop (version 150.0.7871.128) | July 17, 2026 |
| 2026-07-17 | Chrome Releases: Chrome for Android Update (version 150) | July 17, 2026 |
| 2026-07-15 | Chrome Releases: Chrome Stable for iOS Update (version 151) | July 15, 2026 |
| 2026-07-15 | Chrome Releases: Chrome for Android Update (version 150) | July 15, 2026 |
| 2026-07-15 | Chrome Releases: Stable Channel Update for Desktop (version 150.0.7871.124) | July 15, 2026 |
| 2026-07-11 | Chrome Releases: Stable Channel Update for ChromeOS / ChromeOS Flex | July 11, 2026 |
| 2026-07-08 | Chrome Releases: Chrome Stable for iOS Update (version 150) | July 8, 2026 |
Known Exploited Google Vulnerabilities
The following Google vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Google Chromium V8 Out-of-Bounds Read and Write Vulnerability |
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-11645 Exploit Probability: 0.7% |
June 9, 2026 |
| Google Dawn Use-After-Free Vulnerability |
Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-5281 Exploit Probability: 5.5% |
April 1, 2026 |
| Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerabi |
Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-3910 Exploit Probability: 2.1% |
March 13, 2026 |
| Google Skia Out-of-Bounds Write Vulnerability |
Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. CVE-2026-3909 Exploit Probability: 1.6% |
March 13, 2026 |
| Google Chromium CSS Use-After-Free Vulnerability |
Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2026-2441 Exploit Probability: 22.0% |
February 17, 2026 |
| Google Chromium Out of Bounds Memory Access Vulnerability |
Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-14174 Exploit Probability: 22.7% |
December 12, 2025 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption. CVE-2025-13223 Exploit Probability: 4.9% |
November 19, 2025 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine. CVE-2025-10585 Exploit Probability: 5.4% |
September 23, 2025 |
| Google Chromium ANGLE and GPU Improper Input Validation Vulnerability |
Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-6558 Exploit Probability: 9.5% |
July 22, 2025 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-6554 Exploit Probability: 6.6% |
July 2, 2025 |
| Google Chromium V8 Out-of-Bounds Read and Write Vulnerability |
Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-5419 Exploit Probability: 6.5% |
June 5, 2025 |
| Google Chromium Loader Insufficient Policy Enforcement Vulnerability |
Google Chromium contains an insufficient policy enforcement vulnerability that allows a remote attacker to leak cross-origin data via a crafted HTML page. CVE-2025-4664 Exploit Probability: 5.4% |
May 15, 2025 |
| Google Chromium Mojo Sandbox Escape Vulnerability |
Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2025-2783 Exploit Probability: 8.4% |
March 27, 2025 |
| Google Chromium V8 Inappropriate Implementation Vulnerability |
Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-7965 Exploit Probability: 17.2% |
August 28, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-7971 Exploit Probability: 19.3% |
August 26, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-5274 Exploit Probability: 10.0% |
May 28, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. CVE-2024-4947 Exploit Probability: 15.1% |
May 20, 2024 |
| Google Chromium V8 Out-of-Bounds Memory Write Vulnerability |
Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-4761 Exploit Probability: 11.0% |
May 16, 2024 |
| Google Chromium Visuals Use-After-Free Vulnerability |
Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CVE-2024-4671 Exploit Probability: 8.3% |
May 13, 2024 |
| Google Chromium V8 Type Confusion Vulnerability |
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. CVE-2023-4762 Exploit Probability: 38.0% |
February 6, 2024 |
8 known exploited Google vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
Top 10 Riskiest Google Vulnerabilities
Based on the current exploit probability, these Google vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.
| Rank | CVE | EPSS | Vulnerability |
|---|---|---|---|
| 1 | CVE-2023-4863 | 99.7% | Google Chromium Heap-Based Buffer Overflow Vulnerability |
| 2 | CVE-2018-17463 | 84.6% | Google Chromium V8 Remote Code Execution Vulnerability |
| 3 | CVE-2020-6418 | 78.8% | Chromium V8 Type Confusion Vulnerability |
| 4 | CVE-2019-13720 | 73.0% | Google Chrome Use-After-Free Vulnerability |
| 5 | CVE-2021-21220 | 70.4% | Chromium V8 Input Validation Vulnerability |
| 6 | CVE-2021-30551 | 64.7% | Chromium V8 Type Confusion Vulnerability |
| 7 | CVE-2021-30632 | 64.5% | Google Chrome Out-of-bounds write |
| 8 | CVE-2019-5786 | 61.5% | Google Chrome Use-After-Free Vulnerability |
| 9 | CVE-2018-6065 | 60.3% | Google Chromium V8 Integer Overflow Vulnerability |
| 10 | CVE-2021-21224 | 57.7% | Chromium V8 JavaScript Engine Remote Code Execution Vulnerability |
By the Year
In 2026 there have been 2031 vulnerabilities in Google with an average score of 7.2 out of ten. Last year, in 2025 Google had 720 security vulnerabilities published. That is, 1311 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.10.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2031 | 7.23 |
| 2025 | 720 | 7.13 |
| 2024 | 1125 | 7.28 |
| 2023 | 1564 | 6.66 |
| 2022 | 1592 | 6.85 |
| 2021 | 1166 | 7.11 |
| 2020 | 1033 | 6.87 |
| 2019 | 858 | 7.33 |
| 2018 | 570 | 7.43 |
It may take a day or so for new Google vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Google Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-16424 | Jul 21, 2026 |
Use-after-free in Chrome Android GPU (pre-150.0.7871.182) sandbox escapeUse after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-16423 | Jul 21, 2026 |
Chrome UI UAF before 150.0.7871.182Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-16422 | Jul 21, 2026 |
Chrome <150.0.7871.182 Cert Validation CVE-2026-16422Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High) |
|
| CVE-2026-16419 | Jul 21, 2026 |
Chrome ANGLE OOB Read/Write Sandbox Escape v<150.0.7871.182 (Android)Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-16418 | Jul 21, 2026 |
V8 Stack Buffer Overflow in Chrome <150.0.7871.182 (Remote Code Exec)Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-16417 | Jul 21, 2026 |
Uninitialized Use in Skia (Chrome <150.0.7871.182)Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-16416 | Jul 21, 2026 |
Google Chrome <150.0.7871.182 Integer OverFlow in Chromecast Allows SandboxEsc.Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High) |
|
| CVE-2026-16415 | Jul 21, 2026 |
Google Chrome <=150.0.7871.182 Omnibox Spoof via Untrusted InputInsufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-16414 | Jul 21, 2026 |
Chrome Chromecast sandbox escape via untrusted input (before 150.0.7871.182)Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High) |
|
| CVE-2026-16421 | Jul 21, 2026 |
Chrome <150.0.7871.182 Remote Code Exec in WebAudio via Crafted HTMLInappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-16413 | Jul 21, 2026 |
ANGLE OOB write in Chrome <=150.0.7871.182, sandbox escape via crafted HTML pageOut of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-16420 | Jul 21, 2026 |
WebAudio Type Confusion Chrome <150.0.7871.182 Remote Code ExecutionType Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15432 | Jul 21, 2026 |
Timing Leak in Tink ChunkedMacVerification Tag ComparisonWhen verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a given tag match the correct tag. This in turn could allow to find a correct tag bytewise. |
|
| CVE-2026-15829 | Jul 21, 2026 |
SQLi&Bypass in Google BigQuery Forecast Tool (bigquery-forecast)A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and interpolates them unescaped via fmt.Sprintf directly into a generated AI.FORECAST table-valued SELECT statement. While MCP Toolbox utilizes an allowedDatasets mechanism to restrict queries, this defense only validates the history_data parameter; the final assembled query is executed without re-validation. An attacker can break out of the string literal fields (such as timestamp_col) to inject a valid multi-statement or cross-dataset query block. This allows an unauthorized user to bypass the operator-configured allowedDatasets boundary and read arbitrary BigQuery tables. |
|
| CVE-2026-15905 | Jul 20, 2026 |
Use After Free in Aura (Chrome <150.0.7871.128)Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High) |
|
| CVE-2026-15904 | Jul 20, 2026 |
Chrome Ozone UAF via UI Gestures pre-150.0.7871.128Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15903 | Jul 20, 2026 |
Out of bounds read/write in V8 (Chrome <150.0.7871.128) enabling sandbox escapeOut of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15902 | Jul 20, 2026 |
Use-after-free in Chrome Cast (pre-150.0.7871.128) via crafted HTMLUse after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15901 | Jul 20, 2026 |
Chrome Use-After-Free (UF) in Network prior 150.0.7871.128, criticalUse after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) |
|
| CVE-2026-15900 | Jul 20, 2026 |
Google Chrome <150.0.7871.128 Use After Free in GPU (Android)Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
|
| CVE-2026-15899 | Jul 20, 2026 |
Google Chrome Mac <150.0.7871.128 Use-After-Free CameraCapture Sandbox EscapeUse after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) |
|
| CVE-2026-12715 | Jul 17, 2026 |
Firebase Studio Auth Bypass: Unauthorized GCS URL Signing LeakMissing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on 15 April 2026, and no customer action is needed. |
|
| CVE-2026-15778 | Jul 14, 2026 |
Insufficient Validation of Untrusted Input in Navigation (Chrome <150.0.7871.125)Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-15777 | Jul 14, 2026 |
UAF in Chrome UI before 150.0.7871.125 (Linux) Remote Heap CorruptionUse after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15775 | Jul 14, 2026 |
Same-Origin Policy Bypass via V8 in Chrome <150.0.7871.125Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15776 | Jul 14, 2026 |
Arbitrary Code Exec in Chrome V8 <150.0.7871.125 via Crafted HTMLInappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15772 | Jul 14, 2026 |
Use-after-free in Chrome GPU (Android <150.0.7871.125) Sandbox EscapeUse after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15774 | Jul 14, 2026 |
Use-After-Free in Skia (Chrome <150.0.7871.125) Sandbox escape via HTMLUse after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15773 | Jul 14, 2026 |
Use-after-Free in Chrome Core (v<150.0.7871.125)Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15771 | Jul 14, 2026 |
Chrome Media Component Leak: CVE-2026-15771 (<=150.0.7871.124 Windows)Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15770 | Jul 14, 2026 |
Uninitialized Use V8 in Chrome <150.0.7871.125 (CVE-2026-15770)Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15768 | Jul 14, 2026 |
Chrome <150.0.7871.125: HTML-in-CANVAS SOP BypassInsufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15769 | Jul 14, 2026 |
Chrome Linux Toolkit Theming sandbox escape <=150.0.7871.125 (High)Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15767 | Jul 14, 2026 |
libyuv Heap Buffer Overflow in Chrome Windows <150.0.7871.125Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High) |
|
| CVE-2026-15765 | Jul 14, 2026 |
Use-after-free in Chrome Ozone before 150.0.7871.125 (Critical)Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) |
|
| CVE-2026-15766 | Jul 14, 2026 |
Uninitialized Use in Skia (Chrome <150.0.7871.125) - Remote Info LeakageUninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15764 | Jul 14, 2026 |
UAF in Chrome Ozone 150.0.7871.125 via UI GesturesUse after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) |
|
| CVE-2026-14934 | Jul 13, 2026 |
Escalated Access via MissingAuth in GCP BigQuery ReposA Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository takeover. This vulnerability was patched on 10 May 2026, and no customer action is needed. |
|
| CVE-2026-12879 | Jul 09, 2026 |
Google Apigee BigQuery DAO Input Validation Allows Cross-Tenant Data ExfilAn Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed. |
|
| CVE-2026-15131 | Jul 08, 2026 |
Chrome Navigation Site Isolation Bypass <150.0.7871.115Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-15107 | Jul 08, 2026 |
Use-after-Free in Chrome IndexedDB (before 150.0.7871.115)Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) |
|
| CVE-2026-15130 | Jul 08, 2026 |
Insufficient policy enforcement in Chrome Navigation prior to 150.0.7871.115Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15128 | Jul 08, 2026 |
Google Chrome 150.0.7871.115 - Forms UXSS via arbitrary script injectionInappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15125 | Jul 08, 2026 |
Insecure Forms Remote Code Exec in Chrome <150.0.7871.115Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15126 | Jul 08, 2026 |
Google Chrome <150.0.7871.115 UAF in Forms sandboxed execUse after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15127 | Jul 08, 2026 |
Chrome <150.0.7871.115 UXSS via WebGLInappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15123 | Jul 08, 2026 |
Chrome DOM heap corruption CVE-2026-15123 prior to 150.0.7871.115Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15122 | Jul 08, 2026 |
Chrome 150.0.7871.115 Codecs NL sandbox escape via crafted HTMLInsufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15124 | Jul 08, 2026 |
GoogleChrome 150.0.7871.115 Password Policy Bypass (Same-Origin)Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High) |
|
| CVE-2026-15120 | Jul 08, 2026 |
Use-After-Free in Chrome Core (pre-150.0.7871.115) Enables sandbox escapeUse after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) |
|