Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Google

16,977 known vulnerabilities

981
CRITICAL
5,879
HIGH
5,898
MEDIUM
447
LOW

Top Products

android 8109 chrome 4748 tensorflow 431 chrome os 215 asylo 16 blink 12 mcp toolbox for databases 9 linux and chrome os 8 gvisor 7 fuchsia 6
13,206 CVEs · Page 54/265
8.8
CVE-2026-0908

Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap co

9.8
CVE-2026-0907

Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoo

9.8
CVE-2026-0906

Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the content

9.8
CVE-2026-0905

Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a netw

5.4
CVE-2026-0904

Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perfor

5.4
CVE-2026-0903

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker t

8.8
CVE-2026-0902

Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform an out o

5.4
CVE-2026-0901

Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to pe

8.8
CVE-2026-0900

Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially expl

8.8
CVE-2026-0899

Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially explo

7.8
CVE-2025-48647

In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to imprope

7.1
CVE-2025-36911

In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjac

8.8
CVE-2026-0628

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convince

6.7
CVE-2025-20807

In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi

6.7
CVE-2025-20806

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if

6.7
CVE-2025-20805

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if

6.7
CVE-2025-20804

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if

6.7
CVE-2025-20803

In dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privile

6.7
CVE-2025-20802

In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil

7.0
CVE-2025-20801

In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privile

7.8
CVE-2025-20800

In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

7.8
CVE-2025-20799

In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege i

7.8
CVE-2025-20798

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

7.8
CVE-2025-20797

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

7.8
CVE-2025-20796

In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation

7.8
CVE-2025-20795

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio

6.7
CVE-2025-20787

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20786

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20785

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20784

In display, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of priv

6.7
CVE-2025-20783

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

6.7
CVE-2025-20782

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

7.8
CVE-2025-20781

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

7.8
CVE-2025-20780

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

7.0
CVE-2025-20779

In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege

7.8
CVE-2025-20778

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

8.8
CVE-2025-14766

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exp

8.8
CVE-2025-14765

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap

6.2
CVE-2025-65835

The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an export

4.3
CVE-2025-14373

Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to

6.1
CVE-2025-14372

Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially per

8.8
CVE-2025-14174 KEV

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor

6.8
CVE-2025-36938

In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead t

9.8
CVE-2025-36937

In AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect b

7.8
CVE-2025-36936

In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow. Thi

7.8
CVE-2025-36935

In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to uninitialized data. This

7.4
CVE-2025-36934

In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race co

7.8
CVE-2025-36932

In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to imp

7.8
CVE-2025-36931

In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lea

7.8
CVE-2025-36930

In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lea

Frequently Asked Questions

How many CVEs affect Google?

Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Google vulnerabilities?

Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Google vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Google Vulnerabilities

CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.

Get Started