Vulnerabilities in Google
7,001 resultsCVE-2025-13097MEDIUMInappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox EPSS 0.2%CVE-2026-87571MEDIUMImproper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering toEPSS 0.2%CVE-2026-106272MEDIUMUI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineeEPSS 0.2%CVE-2023-40103—In multiple locations, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege withEPSS 0.2%CVE-2026-8005MEDIUMInsufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment EPSS 0.2%CVE-2025-12446MEDIUMIncorrect security UI in SplitView in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in speciEPSS 0.2%CVE-2026-91708LOWRace condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtaEPSS 0.2%CVE-2026-106424MEDIUMInformation leak in Audio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to readEPSS 0.2%CVE-2026-106420MEDIUMIncorrect calculation in API in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering tEPSS 0.2%CVE-2026-67180HIGHGoogle Turbinia arbitrary command executionEPSS 0.2%CVE-2026-11214MEDIUMInappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-originEPSS 0.2%CVE-2024-0033HIGHIn multiple functions of ashmem-dev.cpp, there is a possible missing seal due to a heap buffer overflow. This could lead to local escalationEPSS 0.2%CVE-2026-12018HIGHInappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilEPSS 0.2%CVE-2025-13634MEDIUMInappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to bypass mark of the EPSS 0.2%CVE-2024-47022MEDIUMAndroid before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-331255656.EPSS 0.2%CVE-2024-47020MEDIUMAndroid before 2024-10-05 on Google Pixel devices allows information disclosure in the ABL component, A-331966488.EPSS 0.2%CVE-2026-8565MEDIUMInappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to instalEPSS 0.2%CVE-2026-11150MEDIUMInappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UEPSS 0.2%CVE-2018-9388HIGHIn store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing bounds checks or inEPSS 0.2%CVE-2026-11273MEDIUMInsufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a userEPSS 0.2%