| CVE-2026-0138 | 7.8 | high | google / android | In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. | 81d ago |
| CVE-2026-0137 | 7.8 | high | google / android | In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use | 81d ago |
| CVE-2026-0135 | 7.8 | high | google / android | In Modem, there is a possible out of bounds read due to a missing bounds check. | 81d ago |
| CVE-2026-0133 | 7.8 | high | google / android | In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts | 81d ago |
| CVE-2026-11103 | 7.8 | high | google / chrome | Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attac | 93d ago |
| CVE-2026-11072 | 7.8 | high | google / chrome | Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute a | 93d ago |
| CVE-2026-10942 | 7.8 | high | google / chrome | Inappropriate implementation in UI in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to | 93d ago |
| CVE-2026-28580 | 7.8 | high | google / android | In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. | 96d ago |
| CVE-2026-28577 | 7.8 | high | google / android | In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack | 96d ago |
| CVE-2026-0100 | 7.8 | high | google / android | In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. | 96d ago |
| CVE-2026-0099 | 7.8 | high | google / android | In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background du | 96d ago |
| CVE-2026-0098 | 7.8 | high | google / android | In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a con | 96d ago |
| CVE-2026-0096 | 7.8 | high | google / android | In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due | 96d ago |
| CVE-2026-0094 | 7.8 | high | google / android | In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to | 96d ago |
| CVE-2026-0093 | 7.8 | high | google / android | In multiple locations, there is a possible misleading UI due to obfuscation. | 96d ago |
| CVE-2026-0091 | 7.8 | high | google / android | In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged sh | 96d ago |
| CVE-2026-0089 | 7.8 | high | google / android | In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a | 96d ago |
| CVE-2026-0088 | 7.8 | high | google / android | In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to m | 96d ago |
| CVE-2026-0087 | 7.8 | high | google / android | In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary | 96d ago |
| CVE-2026-0078 | 7.8 | high | google / android | In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper inp | 96d ago |
| CVE-2026-0077 | 7.8 | high | google / android | In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due | 96d ago |
| CVE-2026-0076 | 7.8 | high | google / android | In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. | 96d ago |
| CVE-2026-0045 | 7.8 | high | google / android | In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a l | 96d ago |
| CVE-2026-0036 | 7.8 | high | google / android | In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack | 96d ago |
| CVE-2026-0009 | 7.8 | high | google / android | In multiple locations, there is a possible tapjacking due to a logic error in the code. | 96d ago |
| CVE-2025-48652 | 7.8 | high | google / android | In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic er | 96d ago |
| CVE-2025-48649 | 7.8 | high | google / android | In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions | 96d ago |
| CVE-2025-48570 | 7.8 | high | google / android | In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background | 96d ago |
| CVE-2025-32348 | 7.8 | high | google / android | In multiple locations, there is a possible background activity launch due to a missing permission check. | 96d ago |
| CVE-2025-26418 | 7.8 | high | google / android | In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog | 96d ago |
| CVE-2025-22426 | 7.8 | high | google / android | In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error | 96d ago |
| CVE-2025-22424 | 7.8 | high | google / android | In multiple locations, there is a possible way to reveal images across users due to improper input validation. | 96d ago |
| CVE-2026-0072 | 7.8 | high | google / android xr | In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permissio | 96d ago |
| CVE-2026-9987 | 7.8 | high | google / chrome | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 al | 100d ago |
| CVE-2026-79245 | 7.7 | high | google / chrome | Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the rend | 11d ago |
| CVE-2026-14538 | 7.7 | high | google / mcp toolbox for databases | An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of | 37d ago |
| CVE-2026-11297 | 7.7 | high | google / chrome | Insufficient validation of untrusted input in Reader Mode in Google Chrome on Android prior to 149.0.7827.53 allow | 93d ago |
| CVE-2026-79216 | 7.5 | high | google / chrome | Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the | 11d ago |
| CVE-2026-79139 | 7.5 | high | google / chrome | Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker | 11d ago |
| CVE-2026-79083 | 7.5 | high | google / chrome | Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote atta | 11d ago |
| CVE-2026-78915 | 7.5 | high | google / chrome | Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to | 11d ago |
| CVE-2026-78906 | 7.5 | high | google / chrome | Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute a | 11d ago |
| CVE-2026-78901 | 7.5 | high | google / chrome | Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code i | 11d ago |
| CVE-2026-76020 | 7.5 | high | google / chrome | Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code | 16d ago |
| CVE-2026-19558 | 7.5 | high | google / chrome | Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to | 25d ago |
| CVE-2026-19176 | 7.5 | high | google / chrome | Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the | 30d ago |
| CVE-2026-19165 | 7.5 | high | google / chrome | Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to | 30d ago |
| CVE-2026-19159 | 7.5 | high | google / chrome | Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to | 30d ago |
| CVE-2026-19158 | 7.5 | high | google / chrome | Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convince | 30d ago |
| CVE-2026-19156 | 7.5 | high | google / chrome | Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to | 30d ago |
| CVE-2026-19142 | 7.5 | high | google / chrome | Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to | 30d ago |
| CVE-2026-14541 | 7.5 | high | google / mcp toolbox for databases | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Goo | 37d ago |
| CVE-2026-14539 | 7.5 | high | google / mcp toolbox for databases | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versio | 37d ago |
| CVE-2026-17979 | 7.5 | high | google / chrome | Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sa | 38d ago |
| CVE-2026-17952 | 7.5 | high | google / chrome | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a use | 38d ago |
| CVE-2026-17948 | 7.5 | high | google / chrome | Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a | 38d ago |
| CVE-2026-17930 | 7.5 | high | google / chrome | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote | 38d ago |
| CVE-2026-17916 | 7.5 | high | google / chrome | Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who | 38d ago |
| CVE-2026-17898 | 7.5 | high | google / chrome | Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to ins | 38d ago |
| CVE-2026-17896 | 7.5 | high | google / chrome | Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary | 38d ago |