LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Google

300 CVEs published in the last four months and 12 stories. Exploited flaws first.

Critical256
High44
Medium0
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-11645exploited8.8highchromeOut of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute a89d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-1378210criticalchromeUse after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised th67d ago
CVE-2026-843259.8criticalchromeImproper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker levera4d ago
CVE-2026-137759.8criticalchromeUse after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the re67d ago
CVE-2026-145379.8criticalmcp toolbox for databasesIncorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and 36d ago
CVE-2026-790909.8criticalchromeImproper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveragin11d ago
CVE-2026-141219.8criticalchromeUse after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute67d ago
CVE-2026-141049.8criticalchromeInsufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a rem67d ago
CVE-2026-01269.8criticalandroidIn WC-Radio, there is a possible out of bounds write due to a missing bounds check.81d ago
CVE-2026-791529.8criticalchromeIncorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attack11d ago
CVE-2026-137769.8criticalchromeType Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the r67d ago
CVE-2026-116519.6criticalchromeUse after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary 89d ago
CVE-2026-790569.6criticalchromeUse after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially e11d ago
CVE-2026-116549.6criticalchromeUse after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to poten89d ago
CVE-2026-110219.6criticalchromeInsufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a rem93d ago
CVE-2026-789379.6criticalchromeUse after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveragin11d ago
CVE-2026-138599.6criticalchromeInappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potenti67d ago
CVE-2026-108819.6criticalchromeOut of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potenti93d ago
CVE-2026-109719.6criticalchromeInsufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed 93d ago
CVE-2026-176929.6criticalchromeUse after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who ha38d ago
CVE-2026-178379.6criticalchromeInsufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote at38d ago
CVE-2026-177269.6criticalchromeInteger overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentia38d ago
CVE-2026-178349.6criticalchromeInsufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote a38d ago
CVE-2026-191499.6criticalchromeUse after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially 30d ago
CVE-2026-789359.6criticalchromeUse of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacke11d ago
CVE-2026-789859.6criticalchromeIncorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker lev11d ago
CVE-2026-791509.6criticalchromeUse after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arb11d ago
CVE-2026-140379.6criticalchromeInsufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had c67d ago
CVE-2026-141209.6criticalchromeInappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had67d ago
CVE-2026-110439.6criticalchromeOut of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had comp93d ago
CVE-2026-116979.6criticalchromeInsufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacke89d ago
CVE-2026-110099.6criticalchromeUse after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially 93d ago
CVE-2026-116389.6criticalchromeUse after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perfo89d ago
CVE-2026-164199.6criticalchromeOut of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacke46d ago
CVE-2026-144169.6criticalchromeOut of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perfor66d ago
CVE-2026-143829.6criticalchromeInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attac66d ago
CVE-2026-144179.6criticalchromeUse after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a 66d ago
CVE-2026-144239.6criticalchromeType Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a 66d ago
CVE-2026-159019.6criticalchromeUse after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploi47d ago
CVE-2026-176569.6criticalchromeUse after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a38d ago
CVE-2026-176959.6criticalchromeInappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to 38d ago
CVE-2026-176819.6criticalchromeInsufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.738d ago
CVE-2026-176919.6criticalchromeOut of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to poten38d ago
CVE-2026-177089.6criticalchromeUse after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the 38d ago
CVE-2026-177219.6criticalchromeOut of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perf38d ago
CVE-2026-177589.6criticalchromeHeap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perf38d ago
CVE-2026-178329.6criticalchromeUse after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the 38d ago
CVE-2026-179409.6criticalchromeInsufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.738d ago
CVE-2026-179909.6criticalchromeInsufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote at38d ago
CVE-2026-191719.6criticalchromeUse after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potential30d ago
CVE-2026-789099.6criticalchromeUse after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engine11d ago
CVE-2026-789459.6criticalchromeUse after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engine11d ago
CVE-2026-790529.6criticalchromeUse after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code11d ago
CVE-2026-791499.6criticalchromeUse after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary cod11d ago
CVE-2026-791409.6criticalchromeUse after free in Views in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to execute arb11d ago
CVE-2026-792579.6criticalchromeUse after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary cod11d ago
CVE-2026-792829.6criticalchromeUse after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute11d ago
CVE-2026-143929.6criticalchromeOut of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perfo66d ago
CVE-2026-110669.6criticalchromeInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attac93d ago
CVE-2026-109729.6criticalchromeUse after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially 93d ago
CVE-2026-109669.6criticalchromeInappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potent93d ago
CVE-2026-110299.6criticalchromeInsufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149.0.7827.53 all93d ago
CVE-2026-109909.6criticalchromeUse after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the r93d ago
CVE-2026-138549.6criticalchromeUse after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who had comprom67d ago
CVE-2026-139019.6criticalchromeInsufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who ha67d ago
CVE-2026-138619.6criticalchromeUse after free in Core in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the r67d ago
CVE-2026-138469.6criticalchromeUse after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised67d ago
CVE-2026-140559.6criticalchromeInsufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allo67d ago
CVE-2026-109839.6criticalchromeInsufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attack93d ago
CVE-2026-110529.6criticalchromeType Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had comprom93d ago
CVE-2026-140449.6criticalchromeUse after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the 67d ago
CVE-2026-140939.6criticalchromeUse after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the r67d ago
CVE-2026-141529.6criticalchromeOut of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had co67d ago
CVE-2026-143989.6criticalchromeUse after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a66d ago
CVE-2026-144119.6criticalchromeInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attac66d ago
CVE-2026-144199.6criticalchromeUse after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a 66d ago
CVE-2026-144209.6criticalchromeOut of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentia66d ago
CVE-2026-151139.6criticalchromeUse after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potent59d ago
CVE-2026-159009.6criticalchromeUse after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially47d ago
CVE-2026-176519.6criticalchromeInsufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a re38d ago
CVE-2026-176559.6criticalchromeInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attac38d ago
CVE-2026-176729.6criticalchromeInsufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote 38d ago
CVE-2026-176719.6criticalchromeInsufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attac38d ago
CVE-2026-176739.6criticalchromeInteger overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the38d ago
CVE-2026-176809.6criticalchromeHeap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who ha38d ago
CVE-2026-176879.6criticalchromeType Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the 38d ago
CVE-2026-176889.6criticalchromeUse after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the 38d ago
CVE-2026-111469.6criticalchromeInsufficient validation of untrusted input in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote 93d ago
CVE-2026-177049.6criticalchromeUse after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the 38d ago
CVE-2026-177109.6criticalchromeInappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who38d ago
CVE-2026-177189.6criticalchromeUse after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a38d ago
CVE-2026-177279.6criticalchromeOut of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to poten38d ago
CVE-2026-177499.6criticalchromeInsufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attack38d ago
CVE-2026-178019.6criticalchromeOut of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potenti38d ago
CVE-2026-178049.6criticalchromeUse after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the 38d ago
CVE-2026-178569.6criticalchromeInappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker w38d ago
CVE-2026-179249.6criticalchromeUse after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the re38d ago
CVE-2026-179479.6criticalchromeUse after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perf38d ago
CVE-2026-180159.6criticalchromeInappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to p38d ago
CVE-2026-191579.6criticalchromeOut of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to pote30d ago
CVE-2026-191709.6criticalchromeUse after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potential30d ago

Filter the full tracker by Google

Our coverage of Google

CVE-2026-85046

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Google released a Chrome security update fixing 12 [

malware

Fake Codex Download Uses Google Sites to Deliver macOS Malware

Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users

malware

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]

nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

cloud

Fake Gemini installer delivers Vidar infostealer via Google Colab lure

A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. “During the initial analysis, it was noted that the top search result for the suspicious filename associated pointed to a file hosted on Google Colab, a cloud-based Jupyter notebook plat

vulnerabilitycritical

Google’s AI security agents found 100+ critical software vulnerabilities in just two days

Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories. The tool, called the Agentic Vulnerability Discovery Harness (AVDH), has been running inside Mandiant for ten months. In that

ai

Google’s open-source HEIR lets AI work with data it can’t see

Google’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler toolchain and development platform for homomorphic encryption. It can convert pre-trained AI models designed to operate on unencrypted data into models that process encrypted inputs. The platform helps application developers, compiler engineers, hardw

malwarehigh

Cavern C2 Framework Evolves With DNS and Google Apps Script

Researchers have identified new components in the Cavern command-and-control framework, which is being used by Iranian nation-state actors. The framework now leverages DNS and Google Apps Script to disguise its malicious traffic as legitimate activity. This evolution aims to enhance its stealth capabilities in ongoing attacks targeting entities in Israel.

patch

APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2

Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good taste in disguises. Their Threat Research Unit report tracks a previously undocumented backdoor called PATCHCORD, […]

phishing

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. [...]

cloud

Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal

Google Cloud outlines its roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028. The post Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal appeared first on SecurityWeek.

cloud

Google Cloud Targets 2027 for First Major Post-Quantum Security Milestone

Google Cloud has set a 2027 deadline to mitigate store-now-decrypt-later risks as part of its post-quantum cryptography roadmap, with wider migration goals extending through 2028