{"schema_version":1,"title":"Google vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 3,057 vulnerabilities in Google: 4 in the last 7 days and 1,763 in the last 90 days, 217 of them critical and 91 exploited in the wild. The most recent, CVE-2026-96812, was published on 25 September 2026. 29 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/google","json_url":"https://junglewise.ai/threats/vendors/google.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/google","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":513,"all_time":3057,"critical":217,"exploited":91,"last_7_days":4,"last_30_days":521,"last_90_days":1763,"last_365_days":2901},"latest":[{"cve":"CVE-2026-96812","slug":"cve-2026-96812-improper-exposure-of-resource-to-wrong-sphere-in-the-host-file","title":"Google gVisor improper device exposure in host file helper","severity":"info","exploited":false,"published_at":"2026-09-25T15:17:57.097+00:00","url":"https://junglewise.ai/threats/cve-2026-96812-improper-exposure-of-resource-to-wrong-sphere-in-the-host-file"},{"cve":"CVE-2026-87722","epss":0.0032,"slug":"cve-2026-87722-uncontrolled-resource-consumption-cwe-400-cwe-1333-in-regex","title":"Gerrit Code Review regex denial of service in search predicates","severity":"info","exploited":false,"published_at":"2026-09-24T22:17:02.48+00:00","url":"https://junglewise.ai/threats/cve-2026-87722-uncontrolled-resource-consumption-cwe-400-cwe-1333-in-regex"},{"cve":"CVE-2026-19202","epss":0.0025,"slug":"cve-2026-19202-a-caching-flaw-in-the-toolbox-core-package-of-the-mcp-toolbox-sdk","title":"Google MCP Toolbox SDK Python token cache reuse across audiences","severity":"info","exploited":false,"published_at":"2026-09-22T22:17:11.707+00:00","url":"https://junglewise.ai/threats/cve-2026-19202-a-caching-flaw-in-the-toolbox-core-package-of-the-mcp-toolbox-sdk"},{"cve":"CVE-2026-73513","cvss":7.5,"epss":0.0072,"slug":"cve-2026-73513-envoy-proxy-multiple-vulnerabilities","title":"Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's","severity":"high","exploited":false,"published_at":"2026-09-21T20:17:27.82+00:00","url":"https://junglewise.ai/threats/cve-2026-73513-envoy-proxy-multiple-vulnerabilities"},{"cve":"CVE-2026-93387","cvss":4.3,"epss":0.0025,"slug":"cve-2026-93387-google-chrome-improper-state-validation-in-skia","title":"Google Chrome improper state validation in Skia","severity":"medium","exploited":false,"published_at":"2026-09-17T21:17:56.06+00:00","url":"https://junglewise.ai/threats/cve-2026-93387-google-chrome-improper-state-validation-in-skia"},{"cve":"CVE-2026-93386","cvss":5.4,"epss":0.0025,"slug":"cve-2026-93386-google-chrome-ui-misrepresentation-in-webappinstalls","title":"Google Chrome UI misrepresentation in WebAppInstalls","severity":"medium","exploited":false,"published_at":"2026-09-17T21:17:55.953+00:00","url":"https://junglewise.ai/threats/cve-2026-93386-google-chrome-ui-misrepresentation-in-webappinstalls"},{"cve":"CVE-2026-93385","cvss":6.5,"epss":0.0031,"slug":"cve-2026-93385-google-chrome-information-leak-in-paint","title":"Google Chrome information leak in Paint","severity":"medium","exploited":false,"published_at":"2026-09-17T21:17:55.847+00:00","url":"https://junglewise.ai/threats/cve-2026-93385-google-chrome-information-leak-in-paint"},{"cve":"CVE-2026-93384","cvss":3.7,"epss":0.0025,"slug":"cve-2026-93384-google-chrome-server-side-request-forgery-in-omnibox-on-android","title":"Google Chrome server-side request forgery in Omnibox on Android","severity":"low","exploited":false,"published_at":"2026-09-17T21:17:55.743+00:00","url":"https://junglewise.ai/threats/cve-2026-93384-google-chrome-server-side-request-forgery-in-omnibox-on-android"},{"cve":"CVE-2026-93383","cvss":4.3,"epss":0.0025,"slug":"cve-2026-93383-google-chrome-information-leak-in-permissions","title":"Google Chrome information leak in Permissions","severity":"medium","exploited":false,"published_at":"2026-09-17T21:17:55.637+00:00","url":"https://junglewise.ai/threats/cve-2026-93383-google-chrome-information-leak-in-permissions"},{"cve":"CVE-2026-93382","cvss":8.8,"epss":0.0037,"slug":"cve-2026-93382-google-chrome-use-after-free-in-pdfium","title":"Google Chrome use-after-free in PDFium","severity":"high","exploited":false,"published_at":"2026-09-17T21:17:55.53+00:00","url":"https://junglewise.ai/threats/cve-2026-93382-google-chrome-use-after-free-in-pdfium"},{"cve":"CVE-2026-93381","cvss":8.8,"epss":0.0039,"slug":"cve-2026-93381-google-chrome-buffer-overflow-in-pdfium","title":"Google Chrome buffer overflow in PDFium","severity":"high","exploited":false,"published_at":"2026-09-17T21:17:55.43+00:00","url":"https://junglewise.ai/threats/cve-2026-93381-google-chrome-buffer-overflow-in-pdfium"},{"cve":"CVE-2026-93380","cvss":3.1,"epss":0.002,"slug":"cve-2026-93380-google-chrome-race-condition-in-filesystem","title":"Google Chrome race condition in FileSystem","severity":"low","exploited":false,"published_at":"2026-09-17T21:17:55.32+00:00","url":"https://junglewise.ai/threats/cve-2026-93380-google-chrome-race-condition-in-filesystem"},{"cve":"CVE-2026-93379","cvss":4.3,"epss":0.0025,"slug":"cve-2026-93379-google-chrome-incorrect-authorization-in-orb","title":"Google Chrome incorrect authorization in ORB","severity":"medium","exploited":false,"published_at":"2026-09-17T21:17:55.21+00:00","url":"https://junglewise.ai/threats/cve-2026-93379-google-chrome-incorrect-authorization-in-orb"},{"cve":"CVE-2026-93378","cvss":3.1,"epss":0.0022,"slug":"cve-2026-93378-google-chrome-missing-authorization-in-storage-component","title":"Google Chrome missing authorization in Storage component","severity":"low","exploited":false,"published_at":"2026-09-17T21:17:55.107+00:00","url":"https://junglewise.ai/threats/cve-2026-93378-google-chrome-missing-authorization-in-storage-component"},{"cve":"CVE-2026-93377","cvss":8.8,"epss":0.0044,"slug":"cve-2026-93377-google-chrome-type-confusion-in-v8","title":"Google Chrome type confusion in V8","severity":"high","exploited":false,"published_at":"2026-09-17T21:17:55+00:00","url":"https://junglewise.ai/threats/cve-2026-93377-google-chrome-type-confusion-in-v8"},{"cve":"CVE-2026-93376","cvss":6.3,"epss":0.0011,"slug":"cve-2026-93376-google-chrome-out-of-bounds-read-in-datatransfer","title":"Google Chrome out of bounds read in DataTransfer","severity":"medium","exploited":false,"published_at":"2026-09-17T21:17:54.89+00:00","url":"https://junglewise.ai/threats/cve-2026-93376-google-chrome-out-of-bounds-read-in-datatransfer"},{"cve":"CVE-2026-93375","cvss":8.1,"epss":0.001,"slug":"cve-2026-93375-google-chrome-incorrect-reference-resolution-in-tracing-sandbox","title":"Google Chrome incorrect reference resolution in Tracing sandbox escape","severity":"high","exploited":false,"published_at":"2026-09-17T21:17:54.787+00:00","url":"https://junglewise.ai/threats/cve-2026-93375-google-chrome-incorrect-reference-resolution-in-tracing-sandbox"},{"cve":"CVE-2026-93374","cvss":9.6,"epss":0.0041,"slug":"cve-2026-93374-google-chrome-use-after-free-in-dawn-on-android","title":"Google Chrome use-after-free in Dawn on Android","severity":"critical","exploited":false,"published_at":"2026-09-17T21:17:54.42+00:00","url":"https://junglewise.ai/threats/cve-2026-93374-google-chrome-use-after-free-in-dawn-on-android"},{"cve":"CVE-2026-93373","cvss":9.6,"epss":0.0034,"slug":"cve-2026-93373-google-chrome-use-after-free-in-extensions-sandbox-escape","title":"Google Chrome use-after-free in Extensions sandbox escape","severity":"critical","exploited":false,"published_at":"2026-09-17T21:17:54.29+00:00","url":"https://junglewise.ai/threats/cve-2026-93373-google-chrome-use-after-free-in-extensions-sandbox-escape"},{"cve":"CVE-2026-93372","cvss":9.6,"epss":0.0045,"slug":"cve-2026-93372-google-chrome-buffer-overflow-in-webgl","title":"Google Chrome buffer overflow in WebGL","severity":"critical","exploited":false,"published_at":"2026-09-17T21:17:54.18+00:00","url":"https://junglewise.ai/threats/cve-2026-93372-google-chrome-buffer-overflow-in-webgl"},{"cve":"CVE-2026-15587","slug":"cve-2026-15587-google-security-operations-soar-privilege-escalation-via","title":"Google Security Operations SOAR privilege escalation via authentication header","severity":"high","exploited":false,"published_at":"2026-09-16T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2026-15587-google-security-operations-soar-privilege-escalation-via"},{"cve":"CVE-2026-91749","cvss":9.6,"epss":0.0038,"slug":"cve-2026-91749-google-chrome-use-after-free-in-workers","title":"Google Chrome use-after-free in Workers","severity":"critical","exploited":false,"published_at":"2026-09-15T21:16:48.833+00:00","url":"https://junglewise.ai/threats/cve-2026-91749-google-chrome-use-after-free-in-workers"},{"cve":"CVE-2026-91748","cvss":8.3,"epss":0.0023,"slug":"cve-2026-91748-google-chrome-race-condition-in-extensions-on-mac","title":"Google Chrome race condition in Extensions on Mac","severity":"high","exploited":false,"published_at":"2026-09-15T21:16:48.703+00:00","url":"https://junglewise.ai/threats/cve-2026-91748-google-chrome-race-condition-in-extensions-on-mac"},{"cve":"CVE-2026-91747","cvss":3.1,"epss":0.0025,"slug":"cve-2026-91747-google-chrome-use-after-free-in-skia-graphics-engine","title":"Google Chrome use-after-free in Skia graphics engine","severity":"low","exploited":false,"published_at":"2026-09-15T21:16:48.58+00:00","url":"https://junglewise.ai/threats/cve-2026-91747-google-chrome-use-after-free-in-skia-graphics-engine"},{"cve":"CVE-2026-91746","cvss":4.3,"epss":0.0023,"slug":"cve-2026-91746-google-chrome-integer-overflow-in-compositing","title":"Google Chrome integer overflow in Compositing","severity":"medium","exploited":false,"published_at":"2026-09-15T21:16:48.44+00:00","url":"https://junglewise.ai/threats/cve-2026-91746-google-chrome-integer-overflow-in-compositing"}],"vendor":{"hub":true,"name":"Google","slug":"google","homepage":"https://www.google.com","description":"American technology company that develops search, cloud computing, software, and advertising products.","url":"https://junglewise.ai/threats/vendors/google"},"weekly":[{"week":"2026-06-29","critical":1,"exploited":0,"vulnerabilities":438},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":28},{"week":"2026-07-13","critical":1,"exploited":0,"vulnerabilities":18},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":28},{"week":"2026-07-27","critical":1,"exploited":0,"vulnerabilities":380},{"week":"2026-08-03","critical":2,"exploited":0,"vulnerabilities":5},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-08-24","critical":44,"exploited":0,"vulnerabilities":333},{"week":"2026-08-31","critical":11,"exploited":1,"vulnerabilities":41},{"week":"2026-09-07","critical":37,"exploited":1,"vulnerabilities":324},{"week":"2026-09-14","critical":13,"exploited":1,"vulnerabilities":151},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":4}],"most_severe":[{"cve":"CVE-2025-10585","cvss":9.8,"epss":0.0542,"slug":"cve-2025-10585-google-chrome-type-confusion-in-v8-engine","title":"Google Chrome type confusion in V8 engine","severity":"critical","exploited":true,"published_at":"2025-09-24T17:15:39.473+00:00","url":"https://junglewise.ai/threats/cve-2025-10585-google-chrome-type-confusion-in-v8-engine"},{"cve":"CVE-2024-7971","cvss":9.6,"slug":"cve-2024-7971-google-chromium-v8-type-confusion-vulnerability","title":"Google Chromium V8 Type Confusion Vulnerability","severity":"critical","exploited":true,"published_at":"2024-08-26T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-7971-google-chromium-v8-type-confusion-vulnerability"},{"cve":"CVE-2024-5274","cvss":9.6,"slug":"cve-2024-5274-google-chromium-v8-type-confusion-vulnerability","title":"Google Chromium V8 Type Confusion Vulnerability","severity":"critical","exploited":true,"published_at":"2024-05-28T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-5274-google-chromium-v8-type-confusion-vulnerability"},{"cve":"CVE-2024-4947","cvss":9.6,"slug":"cve-2024-4947-google-chromium-v8-type-confusion-vulnerability","title":"Google Chromium V8 Type Confusion Vulnerability","severity":"critical","exploited":true,"published_at":"2024-05-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-4947-google-chromium-v8-type-confusion-vulnerability"},{"cve":"CVE-2024-4671","cvss":9.6,"slug":"cve-2024-4671-google-chromium-visuals-use-after-free-vulnerability","title":"Google Chromium Visuals Use-After-Free Vulnerability","severity":"critical","exploited":true,"published_at":"2024-05-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-4671-google-chromium-visuals-use-after-free-vulnerability"},{"cve":"CVE-2023-6345","cvss":9.6,"slug":"cve-2023-6345-google-skia-integer-overflow-vulnerability","title":"Google Skia Integer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2023-11-30T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-6345-google-skia-integer-overflow-vulnerability"},{"cve":"CVE-2023-2136","cvss":9.6,"slug":"cve-2023-2136-google-chrome-skia-integer-overflow-vulnerability","title":"Google Chrome Skia Integer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2023-04-21T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-2136-google-chrome-skia-integer-overflow-vulnerability"},{"cve":"CVE-2022-3075","cvss":9.6,"slug":"cve-2022-3075-google-chromium-mojo-insufficient-data-validation-vulnerability","title":"Google Chromium Mojo Insufficient Data Validation Vulnerability","severity":"critical","exploited":true,"published_at":"2022-09-08T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3075-google-chromium-mojo-insufficient-data-validation-vulnerability"},{"cve":"CVE-2020-16017","cvss":9.6,"slug":"cve-2020-16017-google-chrome-use-after-free-vulnerability","title":"Google Chrome Use-After-Free Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-16017-google-chrome-use-after-free-vulnerability"},{"cve":"CVE-2020-16010","cvss":9.6,"slug":"cve-2020-16010-google-chrome-for-android-ui-heap-buffer-overflow-vulnerability","title":"Google Chrome for Android UI Heap Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-16010-google-chrome-for-android-ui-heap-buffer-overflow-vulnerability"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Google Chrome","slug":"chrome","vulnerabilities":2529,"url":"https://junglewise.ai/threats/technologies/chrome"},{"name":"Google Android","slug":"android","vulnerabilities":356,"url":"https://junglewise.ai/threats/technologies/android"},{"name":"Google Chrome for iOS","slug":"chrome-for-ios","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/chrome-for-ios"},{"name":"Google Chromium V8","slug":"chromium-v8","vulnerabilities":41,"url":"https://junglewise.ai/threats/technologies/chromium-v8"},{"name":"Google Chromium","slug":"chromium","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/chromium"},{"name":"Google TensorFlow","slug":"tensorflow","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/tensorflow"},{"name":"Google Cloud Platform","slug":"google-cloud-platform","vulnerabilities":29,"url":"https://junglewise.ai/threats/technologies/google-cloud-platform"},{"name":"Google Android Framework","slug":"android-framework","vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/android-framework"},{"name":"Google Chrome for Android","slug":"chrome-for-android","vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/chrome-for-android"},{"name":"Google ChromeOS","slug":"chromeos","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/chromeos"},{"name":"Google Pixel Bootloader","slug":"pixel-bootloader","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/pixel-bootloader"},{"name":"Google WebView","slug":"webview","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/webview"},{"name":"Google A2ui\\","slug":"a2ui","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/a2ui"},{"name":"Google Pixel Firmware","slug":"pixel-firmware","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/pixel-firmware"},{"name":"Google MCP Toolbox","slug":"mcp-toolbox","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/mcp-toolbox"},{"name":"Google MCP Toolbox for Databases","slug":"mcp-toolbox-for-databases","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/mcp-toolbox-for-databases"},{"name":"Google Pixel Modem","slug":"pixel-modem","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/pixel-modem"},{"name":"Google Pixel Devices","slug":"pixel-devices","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/pixel-devices"},{"name":"Google Libpixelimsmedia","slug":"libpixelimsmedia","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/libpixelimsmedia"},{"name":"Google Chrome Os","slug":"chrome-os","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/chrome-os"},{"name":"Google Angular Compiler","slug":"compiler","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/compiler"},{"name":"Google Angular","slug":"platform-server","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/platform-server"},{"name":"Google Protobuf","slug":"protobuf","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/protobuf"},{"name":"Google Angular Common","slug":"angular-common","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/angular-common"},{"name":"Google Chrome WebView","slug":"chrome-webview","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/chrome-webview"},{"name":"Google Gemini-Cli","slug":"gemini-cli","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/gemini-cli"},{"name":"Google Go-Attestation","slug":"go-attestation","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/go-attestation"},{"name":"Google Skia","slug":"skia","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/skia"},{"name":"Google Angular SSR","slug":"ssr","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/ssr"}]}