2,047 known vulnerabilities affecting google products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-17864 | Medium | 0.1% | 7.8 | Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7… | |
| CVE-2026-57012 | Medium | 0.1% | 8.4 | In the Setup Wizard, there is a possible remote package install due to a missing… | |
| CVE-2025-48565 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible way to bypass the cross profile inten… | |
| CVE-2026-21733 | Medium | 0.1% | 7.3 | Software installed and run as a non-privileged user may conduct improper GPU sys… | |
| CVE-2026-9987 | Medium | 0.1% | 7.8 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on… | |
| CVE-2025-48566 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible permission bypass due to a confused d… | |
| CVE-2026-79286 | Medium | 0.1% | 7.4 | Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.… | |
| CVE-2026-28639 | Medium | 0.1% | 7.8 | In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write d… | |
| CVE-2026-87554 | Medium | 0.1% | 8.1 | Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.… | |
| CVE-2026-11297 | Medium | 0.1% | 7.7 | Insufficient validation of untrusted input in Reader Mode in Google Chrome on An… | |
| CVE-2026-79057 | Medium | 0.1% | 8.1 | Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 al… | |
| CVE-2026-0008 | Medium | 0.1% | 8.4 | In multiple functions of FaceEnroll.kt, there is a possible privilege escalation… | |
| CVE-2025-22424 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible way to reveal images across users due… | |
| CVE-2026-0009 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible tapjacking due to a logic error in th… | |
| CVE-2026-78892 | Medium | 0.1% | 7.1 | Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 15… | |
| CVE-2026-84334 | Medium | 0.1% | 8.1 | Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 15… | |
| CVE-2025-22426 | Medium | 0.1% | 7.8 | In many functions of ComputerEngine.java, there is a possible way to access URIs… | |
| CVE-2025-48652 | Medium | 0.1% | 7.8 | In performPreInstallChecks of InstallRepository.kt, there is a possible way to b… | |
| CVE-2026-0045 | Medium | 0.1% | 7.8 | In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding… | |
| CVE-2026-11158 | Medium | 0.1% | 8.6 | Insufficient validation of untrusted input in Downloads in Google Chrome on Mac … | |
| CVE-2026-28658 | Medium | 0.1% | 7.8 | In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a l… | |
| CVE-2026-0077 | Medium | 0.1% | 7.8 | In resumeConfigurationDispatch of ActivityRecord.java, there is a possible backg… | |
| CVE-2026-0087 | Medium | 0.1% | 7.8 | In approvalLevelForDomainInternal of DomainVerificationService.java, there is a … | |
| CVE-2026-56970 | Medium | 0.1% | 8.4 | In multiple locations, there is a possible permission bypass due to a missing pe… | |
| CVE-2026-58678 | Medium | 0.1% | 7.8 | In Bootloader, there is a possible permission bypass due to a logic error in the… | |
| CVE-2026-58679 | Medium | 0.1% | 8.4 | In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overfl… | |
| CVE-2026-58691 | Medium | 0.1% | 8.4 | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper… | |
| CVE-2026-8497 | Medium | 0.1% | 7.4 | Improper certificate validation in the Devolutions Server connection handling in… | |
| CVE-2026-11103 | Medium | 0.1% | 7.8 | Inappropriate implementation in Installer in Google Chrome on Windows prior to 1… | |
| CVE-2026-17993 | Medium | 0.1% | 7.0 | Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a loc… | |
| CVE-2025-48649 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible way to reset user-selected permission… | |
| CVE-2026-0076 | Medium | 0.1% | 7.8 | In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due… | |
| CVE-2026-0078 | Medium | 0.1% | 7.8 | In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync… | |
| CVE-2026-0088 | Medium | 0.1% | 7.8 | In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a s… | |
| CVE-2026-11035 | Medium | 0.1% | 7.3 | Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to… | |
| CVE-2026-11115 | Medium | 0.1% | 7.3 | Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 all… | |
| CVE-2026-87457 | Medium | 0.1% | 8.1 | Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 … | |
| CVE-2026-87467 | Medium | 0.1% | 8.1 | Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 … | |
| CVE-2026-28612 | Medium | 0.1% | 7.8 | In resolveActivity of ActivityStarter.java, there is a possible way to perform I… | |
| CVE-2026-56982 | Medium | 0.1% | 7.8 | In VPU, there is a possible permission bypass due to a missing permission check.… | |
| CVE-2026-0065 | Medium | 0.1% | 7.8 | In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java,… | |
| CVE-2026-0084 | Medium | 0.1% | 7.8 | In multiple functions of HostEmulationManager.java, there is a possible backgrou… | |
| CVE-2026-28583 | Medium | 0.1% | 7.8 | In validate_camera_metadata_structure of camera_metadata.c, there is a possible … | |
| CVE-2026-28594 | Medium | 0.1% | 7.8 | In multiple locations, there is a possible use after free due to a logic error i… | |
| CVE-2026-28599 | Medium | 0.1% | 7.8 | In addCreatorToken of ActivityManagerService.java, there is a possible Intent Re… | |
| CVE-2026-28634 | Medium | 0.1% | 7.8 | In handleUssdRequest of PhoneInterfaceManager.java, there is a possible way to s… | |
| CVE-2026-28642 | Medium | 0.1% | 7.8 | In executeRequest of ActivityStarter.java, there is a possible background activi… | |
| CVE-2026-28650 | Medium | 0.1% | 7.8 | In setHiddenWhileSuspended of WindowState.java, there is a possible overlay bypa… | |
| CVE-2026-28655 | Medium | 0.1% | 7.8 | In multiple functions of RemoteViews.java, there is a possible background activi… | |
| CVE-2026-56978 | Medium | 0.1% | 8.4 | In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read d… |