16,977 known vulnerabilities
Top Products
Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged
Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap
Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit hea
Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit
Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the rende
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completi
Google Nest WiFi Pro root code-execution & user-data compromise
There is a possible information disclosure due to a missing permission check. This could lead to local information discl
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege
In bluetooth service, there is a possible out of bounds write due to improper input validation. This could lead to local
In Modem IMS Call UA, there is a possible out of bounds write due to a missing bounds check. This could lead to remote d
In display drm, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation
In netdagent, there is a possible information disclosure due to an incorrect bounds check. This could lead to local esca
In Engineer Mode, there is a possible out of bounds write due to a missing bounds check. This could lead to local escala
In battery, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of
In battery, there is a possible information disclosure due to an integer overflow. This could lead to local information
In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local informati
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In battery, there is a possible information disclosure due to a missing bounds check. This could lead to local informati
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local inform
In keyInstall, there is a possible information disclosure due to a missing bounds check. This could lead to local inform
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit
Insufficient policy enforcement in ADB in Google Chrome on ChromeOS prior to 114.0.5735.90 allowed a local attacker to b
Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displaye
In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subs
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary.
Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap cor
Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engag
Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap
Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap
Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap c
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corr
An oversight in BCB handling of reboot reason that allows for persistent code execution
U-Boot vulnerability resulting in persistent Code Execution
U-Boot shell vulnerability resulting in Privilege escalation in a production device
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application
In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This coul
In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead
In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/platform/pixel/pixel_gpu_slc.c
there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System
In multiple locations, there is a possible null dereference due to a missing null check. This could lead to remote denia
In Init of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could le
In the Pixel Camera Driver, there is a possible use after free due to a logic error in the code. This could lead to loca
In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead
In private_handle_t of mali_gralloc_buffer.h, there is a possible information leak due to a logic error in the code. Th
In SignalStrengthAdapter::FillGsmSignalStrength() of protocolmiscadapter.cpp, there is a possible out of bounds read due
In cd_ParseMsg of cd_codec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to r
Frequently Asked Questions
How many CVEs affect Google?
Google has 16,977 CVE records in our database, including 1160 critical and 8152 high severity vulnerabilities. 94 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Google vulnerabilities?
Google has 1160 critical severity (CVSS 9.0+) and 8152 high severity (CVSS 7.0-8.9) vulnerabilities. 94 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Google vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Google products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Google Vulnerabilities
CyberStrike scans your infrastructure for Google vulnerabilities and provides real-time remediation guidance.
Get Started