VulnSea

google has 753 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 614 in the last 90 days against 97 in the 90 before. The busiest recent month was September 2026 with 501. The median CVSS is 7.5 (high), with 91 rated critical. 1% have been exploited in the wild, in line with the corpus average. When CISA adds a google CVE to KEV it happens fast: a median of 1 day after publication (9 cases). The dominant weakness classes are CWE-416 (91) and CWE-20 (70). Most affected products: chrome (491), android (232), mcp_toolbox_for_databases (7).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
1% vs 1% corpus
Median CVSS
7.5
Publish → KEV
1 d median(9)
Last 90 days
614 prev 97

Products

  • chrome 491
  • android 232
  • mcp_toolbox_for_databases 7
  • github.com/google/cel-go 2
  • github.com/google/exposure-notifications-verification-server 2
  • github.com/google/go-attestation 2
753
Total CVEs
91
Critical
10
CISA KEV
10
Exploited

google vulnerabilities

CVEs affecting google, newest first. Open any entry for full detail, references, and exploit status.

753 CVEsRSS

CVE-2026-79203Low· 3.1
1mo ago

Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page

Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.26%via CVEORG
CVE-2026-79241Medium· 6.5
1mo ago

Out of bounds read in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page

Out of bounds read in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.32%via CVEORG
CVE-2026-79258Medium· 6.5
1mo ago

Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page

Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.32%via CVEORG
CVE-2026-79255Low· 3.1
1mo ago

Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page

Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.27%via CVEORG
CVE-2026-79250Medium· 5.4
1mo ago

UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page

UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.26%via CVEORG
CVE-2026-79283Medium· 5.4
1mo ago

UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page

UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.26%via CVEORG
CVE-2026-78953Low· 3.1
1mo ago

Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file

Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.21%via NVD
CVE-2025-36939Medium· 5.7
1mo ago

Multiple vulnerabilities exist in OpenThread's handling of MLE packets

Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion fa…

▾ Sunlitgoogle · nest_wifi_router_firmwareEPSS 0.21%via NVD
GO-2026-6094None
1mo ago

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

▾ Sunlitgoogle · github.com/google/cel-govia OSV
CVE-2026-19175Critical· 9.6
1mo ago

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-19173High· 8.3
1mo ago

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-19171Critical· 9.6
1mo ago

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-19166Critical· 9.6
1mo ago

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.39%via NVD
CVE-2026-19164Critical· 9.6
1mo ago

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-19159High· 7.5
1mo ago

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity…

▾ Twilightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-19158High· 7.5
1mo ago

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium securi…

▾ Twilightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-19156High· 7.5
1mo ago

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security sev…

▾ Twilightgoogle · chromeEPSS 0.25%via NVD
CVE-2026-19152High· 8.3
1mo ago

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security…

▾ Twilightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-19148High· 8.3
1mo ago

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity:…

▾ Twilightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-19143High· 8.6
1mo ago

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.13%via NVD
CVE-2026-19141High· 8.3
1mo ago

Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severi…

▾ Twilightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-0163Critical· 9.8PoC
1mo ago

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi…

▾ Abyssalgoogle · androidEPSS 0.38%via NVD
CVE-2026-10032Medium· 6.1
1mo ago

The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme

The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI as the url argument of a Button component's functionCall ac…

▾ Sunlitgoogle · a2ui/web_coreEPSS 0.13%via NVD
CVE-2026-14541High· 7.5
1mo ago

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defin…

▾ Twilightgoogle · mcp_toolbox_for_databasesEPSS 0.25%via NVD
CVE-2026-14540Medium· 6.1
1mo ago

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled par…

▾ Sunlitgoogle · mcp_toolbox_for_databasesEPSS 0.13%via NVD
CVE-2026-14539High· 7.5
1mo ago

An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS)

An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handl…

▾ Twilightgoogle · mcp_toolbox_for_databasesEPSS 0.24%via NVD
CVE-2026-14538High· 7.7
1mo ago

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation che…

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation che…

▾ Twilightgoogle · mcp_toolbox_for_databasesEPSS 0.20%via NVD
CVE-2026-14537Critical· 9.8
1mo ago

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocatio…

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocatio…

▾ Midnightgoogle · mcp_toolbox_for_databasesEPSS 0.25%via NVD
CVE-2026-17713Critical· 9.6
2mo ago

Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML …

Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML …

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-17701Critical· 9.6
2mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chrom…

▾ Midnightgoogle · chromeEPSS 0.33%via NVD
google vulnerabilities (CVEs) — page 19 · VulnSea