VulnSea

google has 753 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 615 in the last 90 days against 97 in the 90 before. The busiest recent month was September 2026 with 500. The median CVSS is 7.5 (high), with 91 rated critical. 1% have been exploited in the wild, in line with the corpus average. When CISA adds a google CVE to KEV it happens fast: a median of 1 day after publication (9 cases). The dominant weakness classes are CWE-416 (91) and CWE-20 (70). Most affected products: chrome (492), android (232), mcp_toolbox_for_databases (6).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
1% vs 1% corpus
Median CVSS
7.5
Publish → KEV
1 d median(9)
Last 90 days
615 prev 97

Products

  • chrome 492
  • android 232
  • mcp_toolbox_for_databases 6
  • github.com/google/cel-go 2
  • github.com/google/exposure-notifications-verification-server 2
  • github.com/google/go-attestation 2
753
Total CVEs
91
Critical
10
CISA KEV
10
Exploited

Google vulnerabilities

CVEs affecting Google, newest first. Open any entry for full detail, references, and exploit status.

753 CVEsRSS

CVE-2026-58710High· 8.8
1w ago

In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check

In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed…

▾ Twilightgoogle · androidEPSS 0.37%via NVD
CVE-2026-58704High· 8.8CISA KEV0dayPoC
1w ago

In Cellular Modem, there is a possible permission bypass due to a logic error in the code

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…

▾ Abyssalgoogle · androidEPSS 0.59%via NVD
CVE-2026-58691High· 8.4
1w ago

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-58718Medium· 6.7
1w ago

In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation

In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not n…

▾ Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58716Medium· 6.7
1w ago

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-58695High· 7.8
1w ago

In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check

In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction i…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-58721Medium· 4.4
1w ago

In multiple locations, there is a possible information disclosure due to uninitialized memory use

In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.09%via NVD
CVE-2026-62139Medium· 4.3
2w ago

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

▾ SunlitGoogle · google-site-kitEPSS 0.10%via NVD
CVE-2026-83530Medium· 4.3⚖ disputed
2w ago

A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be …

A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be …

▾ Sunlitgoogle · common_expression_languageEPSS 0.15%via NVD
CVE-2026-87633High· 8.6
2w ago

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.15%via NVD
CVE-2026-87628High· 8.3
2w ago

Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic

Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)

▾ Twilightgoogle · chromeEPSS 0.19%via NVD
CVE-2026-87585High· 8.8
2w ago

Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file

Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.38%via NVD
CVE-2026-87578High· 8.3
2w ago

Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic

Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.19%via NVD
CVE-2026-87569High· 8.8
2w ago

Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-87527Critical· 9.6
2w ago

Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.51%via NVD
CVE-2026-87525Low· 2.7⚖ disputed
2w ago

Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program

Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.11%via NVD
CVE-2026-87524High· 8.3
2w ago

Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium …

▾ Twilightgoogle · chromeEPSS 0.40%via NVD
CVE-2026-87517Low· 3.1
2w ago

Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page

Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.19%via NVD
CVE-2026-87512Critical· 9.6
2w ago

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-87488Critical· 9.6
2w ago

Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-87464Critical· 9.6
2w ago

Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.58%via NVD
CVE-2026-87447Medium· 6.5
2w ago

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.26%via NVD
CVE-2026-87444High· 8.8
2w ago

Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-87440High· 8.8
2w ago

Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-87438Critical· 9.6
2w ago

Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-87654Critical· 9.6
2w ago

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.51%via NVD
CVE-2026-87651Medium· 4.3⚖ disputed
2w ago

Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page

Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-87650Critical· 9.6
2w ago

Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-87647Low· 3.4⚖ disputed
2w ago

Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page

Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-87646Critical· 9.6
2w ago

Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.53%via NVD
Google vulnerabilities (CVEs) — page 6 · VulnSea