Google Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Google products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

90

In CISA KEV

90

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Google KEVs Added by Year

Loading...

90 Google KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2026-11645

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox...

Confirmed In CISA 09 Jun 2026
CVE-2025-48595

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of...

Confirmed In CISA 02 Jun 2026
CVE-2026-5281

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute...

Confirmed In CISA 01 Jun 2026
CVE-2026-3910

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via...

Confirmed In CISA 01 Jun 2026
CVE-2026-3909

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted...

Confirmed In CISA 01 Jun 2026
CVE-2026-2441

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted...

Confirmed In CISA 01 Jun 2026
CVE-2025-14174

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory...

Confirmed In CISA 01 Jun 2026
CVE-2025-48633

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error...

Confirmed In CISA 01 Jun 2026
CVE-2025-48572

In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local...

Confirmed In CISA 01 Jun 2026
CVE-2025-13223

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Confirmed In CISA 01 Jun 2026
CVE-2025-10585

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Confirmed In CISA 01 Jun 2026
CVE-2025-48543

In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use after free. This could lead to...

Confirmed In CISA 01 Jun 2026
CVE-2025-6558

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially...

Confirmed In CISA 01 Jun 2026
CVE-2025-6554

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page....

Confirmed In CISA 01 Jun 2026
CVE-2025-5419

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a...

Confirmed In CISA 01 Jun 2026
CVE-2021-30563

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Confirmed In CISA 03 Nov 2021
CVE-2021-21220

Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap...

Confirmed In CISA 03 Nov 2021
CVE-2021-21193

Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Confirmed In CISA 03 Nov 2021
CVE-2021-21224

Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML...

Confirmed In CISA 03 Nov 2021
CVE-2021-38003

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a...

Confirmed In CISA 03 Nov 2021
CVE-2021-38000

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily...

Confirmed In CISA 03 Nov 2021
CVE-2021-21206

Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Confirmed In CISA 03 Nov 2021
CVE-2021-30554

Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Confirmed In CISA 03 Nov 2021
CVE-2020-6418

Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Confirmed In CISA 03 Nov 2021
CVE-2021-37975

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Confirmed In CISA 03 Nov 2021

Common Vulnerability Classes (CWE)

  • CWE-416 — Use After Free 20
  • CWE-787 — Out-of-bounds Write 19
  • CWE-843 — Access of Resource Using Incompatible Type ('Type Confusion') 19
  • CWE-190 — Integer Overflow or Wraparound 5
  • CWE-125 — Out-of-bounds Read 5
  • CWE-20 — Improper Input Validation 5
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 2
  • CWE-122 — Heap-based Buffer Overflow 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology