Google vendor intelligence

Google Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Google products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Google KEVs Full KEV feed
Total KEVs
93
Known exploited vulnerabilities affecting Google products
In CISA KEV
92
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
Google KEVs with sensor-observed exploitation activity

The catalog gap matters for Google exposure

One of the 93 exploited Google vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 1% of this vendor portfolio.

99%
Covered by CISA
1%
Beyond CISA
9
Product families

Attested Google vulnerabilities

93 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-87491

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a...

Chrome Confirmed In CISA 09 Sep 2026
CVE-2026-85046

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted...

Chrome Confirmed In CISA 04 Sep 2026
CVE-2026-11645

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox...

Chrome Confirmed In CISA 09 Jun 2026
CVE-2025-48595

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of...

Android Confirmed In CISA 02 Jun 2026
CVE-2022-0346

Google XML Sitemap Generator < 2.0.4 - Reflected Cross-Site Scripting

XML Sitemap Generator High Beyond CISA 26 Mar 2026
CVE-2026-5281

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute...

Chrome Confirmed In CISA 01 Jun 2026
CVE-2026-3910

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via...

Chrome Confirmed In CISA 01 Jun 2026
CVE-2026-3909

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted...

Chrome Confirmed In CISA 01 Jun 2026
CVE-2026-2441

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted...

Chrome Confirmed In CISA 01 Jun 2026
CVE-2025-14174

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory...

Chrome Confirmed In CISA 01 Jun 2026
CVE-2025-48633

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error...

Android Confirmed In CISA 01 Jun 2026
CVE-2025-48572

In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local...

Android Confirmed In CISA 01 Jun 2026
CVE-2025-13223

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Chrome Confirmed In CISA 01 Jun 2026
CVE-2025-10585

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Chrome Confirmed In CISA 01 Jun 2026
CVE-2025-48543

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to...

Android Confirmed In CISA 01 Jun 2026
CVE-2025-6558

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially...

Chrome Confirmed In CISA 01 Jun 2026
CVE-2025-6554

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page....

Chrome Confirmed In CISA 01 Jun 2026
CVE-2025-5419

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a...

Chrome Confirmed In CISA 01 Jun 2026
CVE-2021-30563

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-21220

Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-21193

Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-21224

Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-38003

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-38000

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-21206

Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-30554

Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2020-6418

Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-37975

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-30551

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-37973

Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-21148

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-30633

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2020-16013

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-30632

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2020-16009

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-37976

Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2020-16017

Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2021-21166

Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Chrome Confirmed In CISA 03 Nov 2021
CVE-2020-15999

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2020-16010

Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to...

Chrome Confirmed In CISA 03 Nov 2021
CVE-2020-0041

In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of...

Android Confirmed In CISA 03 Nov 2021
CVE-2019-2215

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit...

Android Confirmed In CISA 03 Nov 2021
CVE-2021-4102

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Chrome Confirmed In CISA 15 Dec 2021
CVE-2020-6572

Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

Chrome Confirmed In CISA 10 Jan 2022
CVE-2022-0609

Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted...

Chrome Confirmed In CISA 15 Feb 2022
CVE-2022-1096

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Chrome Confirmed In CISA 28 Mar 2022
CVE-2021-39793

In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to...

Android Confirmed In CISA 11 Apr 2022
CVE-2022-1364

Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a...

Chrome Confirmed In CISA 15 Apr 2022
CVE-2019-13720

Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted...

Chrome Confirmed In CISA 23 May 2022
CVE-2019-5786

Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access...

Chrome Confirmed In CISA 23 May 2022

Showing 50 of 50 on this page (93 Google known exploited vulnerabilities).

Recurring weakness patterns

Access, out-of-bounds write, and use after free account for 60 mapped occurrences across this Google KEV portfolio.

Browse all KEVs →