VulnSea

google has 753 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 614 in the last 90 days against 97 in the 90 before. The busiest recent month was September 2026 with 501. The median CVSS is 7.5 (high), with 91 rated critical. 1% have been exploited in the wild, in line with the corpus average. When CISA adds a google CVE to KEV it happens fast: a median of 1 day after publication (9 cases). The dominant weakness classes are CWE-416 (91) and CWE-20 (70). Most affected products: chrome (491), android (232), mcp_toolbox_for_databases (7).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
1% vs 1% corpus
Median CVSS
7.5
Publish → KEV
1 d median(9)
Last 90 days
614 prev 97

Products

  • chrome 491
  • android 232
  • mcp_toolbox_for_databases 7
  • github.com/google/cel-go 2
  • github.com/google/exposure-notifications-verification-server 2
  • github.com/google/go-attestation 2
753
Total CVEs
91
Critical
10
CISA KEV
10
Exploited

google vulnerabilities

CVEs affecting google, newest first. Open any entry for full detail, references, and exploit status.

753 CVEsRSS

CVE-2026-79070Medium· 4.3
1mo ago

Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.33%via CVEORG
CVE-2026-79137Medium· 4.3
1mo ago

Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension

Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.22%via CVEORG
CVE-2026-79087Medium· 4.3
1mo ago

Injection in Chrome Tabs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass system access restrictions via a crafted HTML page

Injection in Chrome Tabs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.25%via CVEORG
CVE-2026-79192Medium· 4.3
1mo ago

Improper input validation in Variations in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via crafted network traffic

Improper input validation in Variations in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.25%via CVEORG
CVE-2026-79205Medium· 4.3
1mo ago

Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.27%via CVEORG
CVE-2026-79201Medium· 4.3
1mo ago

Improper access control in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Improper access control in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.27%via CVEORG
CVE-2026-79190Medium· 4.3
1mo ago

Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page

Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

▾ SunlitGoogle · ChromeEPSS 0.27%via CVEORG
CVE-2026-79248Medium· 4.3
1mo ago

Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page

Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.29%via CVEORG
CVE-2026-79213Medium· 4.3
1mo ago

Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page

Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.26%via CVEORG
CVE-2026-79211Medium· 4.3
1mo ago

Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.24%via CVEORG
CVE-2026-79238Medium· 4.3
1mo ago

Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension

Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.26%via CVEORG
CVE-2026-79276Medium· 4.3
1mo ago

Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.28%via CVEORG
CVE-2026-79264Medium· 4.3
1mo ago

Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.33%via CVEORG
CVE-2026-79259Medium· 4.3
1mo ago

Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file

Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.23%via CVEORG
CVE-2026-78940Medium· 4.3
1mo ago

Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.33%via CVEORG
CVE-2026-78903Low· 3.1PoC
1mo ago

Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page

Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

▾ TwilightGoogle · ChromeEPSS 0.29%via CVEORG
CVE-2026-78912Medium· 5.4
1mo ago

UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page

UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.26%via CVEORG
CVE-2026-78949Low· 2.9
1mo ago

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.11%via CVEORG
CVE-2026-78936Low· 2.9
1mo ago

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app

Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.11%via CVEORG
CVE-2026-79031Low· 3.1
1mo ago

Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a crafted HTML page

Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.24%via CVEORG
CVE-2026-78967Medium· 6.5
1mo ago

Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page

Missing authorization in BFCache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.29%via CVEORG
CVE-2026-79053Low· 3.1
1mo ago

Missing authorization in Lighthouse in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page

Missing authorization in Lighthouse in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium s…

▾ SunlitGoogle · ChromeEPSS 0.23%via CVEORG
CVE-2026-79002Low· 3.1
1mo ago

Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page

Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.23%via CVEORG
CVE-2026-79089Medium· 5.3
1mo ago

Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severi…

▾ SunlitGoogle · ChromeEPSS 0.21%via CVEORG
CVE-2026-79077Medium· 4.3
1mo ago

Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page

Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

▾ SunlitGoogle · ChromeEPSS 0.26%via CVEORG
CVE-2026-79066Low· 3.1
1mo ago

Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page

Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.26%via CVEORG
CVE-2026-79146Medium· 5.5
1mo ago

Information leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app

Information leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.12%via CVEORG
CVE-2026-79103Low· 3.1
1mo ago

Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page

Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.29%via CVEORG
CVE-2026-79180Medium· 5.4
1mo ago

UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page

UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.26%via CVEORG
CVE-2026-79204Medium· 5.4
1mo ago

UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page

UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.26%via CVEORG
google vulnerabilities (CVEs) — page 18 · VulnSea