Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Google

8,977 known vulnerabilities

532
CRITICAL
2,831
HIGH
2,023
MEDIUM
123
LOW

Top Products

chrome 3022 android 2607 chrome os 139 blink 12 mcp toolbox for databases 9 tensorflow 7 nest cam iq indoor firmware 6 nest cam iq indoor 5 nexus 9 4 rendertron 4
5,510 CVEs · Page 4/111
4.3
CVE-2026-79009

UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeri

8.3
CVE-2026-79008

Improper input validation in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had

4.3
CVE-2026-79006

Protection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypas

6.5
CVE-2026-79005

Incorrect authorization in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had co

3.1
CVE-2026-79002

Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr

5.3
CVE-2026-79001

Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compro

4.3
CVE-2026-79000

Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote atta

8.3
CVE-2026-78999

Improper privilege management in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had co

5.3
CVE-2026-78991

Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r

8.8
CVE-2026-78990

Use after free in Compositing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary cod

9.6
CVE-2026-78989

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potential

4.3
CVE-2026-78987

Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy

9.6
CVE-2026-78985

Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveragin

8.3
CVE-2026-78983

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the render

6.5
CVE-2026-78981

Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obt

4.3
CVE-2026-78980

Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging soc

4.3
CVE-2026-78979

Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social

8.8
CVE-2026-78978

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potential

6.5
CVE-2026-78977

Uninitialized resource in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potenti

4.3
CVE-2026-78976

Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had

6.5
CVE-2026-78975

Incorrect authorization in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf

6.5
CVE-2026-78968

Missing authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the

4.3
CVE-2026-78966

Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web

9.6
CVE-2026-78964

Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execut

8.8
CVE-2026-78963

Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec

4.3
CVE-2026-78962

Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi

4.3
CVE-2026-78961

Incorrect authorization in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised th

8.8
CVE-2026-78956

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to

4.3
CVE-2026-78954

Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromi

3.1
CVE-2026-78953

Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had comprom

8.3
CVE-2026-78952

Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had

9.6
CVE-2026-78951

Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary c

8.8
CVE-2026-78950

Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbi

9.6
CVE-2026-78948

Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code out

6.5
CVE-2026-78947

Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin

4.3
CVE-2026-78946

Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin

9.6
CVE-2026-78945

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering

8.8
CVE-2026-78944

Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeri

3.1
CVE-2026-78943

Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis

4.3
CVE-2026-78942

Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web

4.3
CVE-2026-78940

Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origi

9.6
CVE-2026-78939

Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r

8.8
CVE-2026-78938

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside

9.6
CVE-2026-78937

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging soci

9.6
CVE-2026-78935

Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to p

8.3
CVE-2026-78934

Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineer

7.5
CVE-2026-78915

Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to poten

6.5
CVE-2026-78914

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read mem

8.1
CVE-2026-78913

Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar

5.4
CVE-2026-78912

UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements v

Frequently Asked Questions

How many CVEs affect Google?

Google has 8,977 CVE records in our database, including 672 critical and 3773 high severity vulnerabilities. 20 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Google vulnerabilities?

Google has 672 critical severity (CVSS 9.0+) and 3773 high severity (CVSS 7.0-8.9) vulnerabilities. 20 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Google vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Google Vulnerabilities

CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.

Get Started