Google Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Google products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

90

In CISA KEV

90

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Google KEVs Added by Year

Loading...

90 Google KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2016-5198

V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect...

Confirmed In CISA 08 Jun 2022
CVE-2017-5030

Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android...

Confirmed In CISA 08 Jun 2022
CVE-2017-5070

Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to...

Confirmed In CISA 08 Jun 2022
CVE-2018-17463

Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox...

Confirmed In CISA 08 Jun 2022
CVE-2018-17480

Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80...

Confirmed In CISA 08 Jun 2022
CVE-2018-6065

Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146...

Confirmed In CISA 08 Jun 2022
CVE-2019-5825

Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a...

Confirmed In CISA 08 Jun 2022
CVE-2021-30533

Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions...

Confirmed In CISA 27 Jun 2022
CVE-2022-2856

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily...

Confirmed In CISA 18 Aug 2022
CVE-2022-2294

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a...

Confirmed In CISA 25 Aug 2022
CVE-2011-1823

The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local...

Confirmed In CISA 08 Sep 2022
CVE-2022-3075

Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to...

Confirmed In CISA 08 Sep 2022
CVE-2022-3723

Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Confirmed In CISA 28 Oct 2022
CVE-2022-4135

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to...

Confirmed In CISA 28 Nov 2022
CVE-2022-4262

Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Confirmed In CISA 05 Dec 2022
CVE-2022-3038

Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a...

Confirmed In CISA 30 Mar 2023
CVE-2023-20963

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges...

Confirmed In CISA 13 Apr 2023
CVE-2023-2033

Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Confirmed In CISA 17 Apr 2023
CVE-2023-2136

Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially...

Confirmed In CISA 21 Apr 2023
CVE-2023-3079

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...

Confirmed In CISA 07 Jun 2023
CVE-2023-4863

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds...

Confirmed In CISA 13 Sep 2023
CVE-2023-35674

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local...

Confirmed In CISA 13 Sep 2023
CVE-2023-5217

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially...

Confirmed In CISA 02 Oct 2023
CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as...

Confirmed In CISA 10 Oct 2023
CVE-2023-6345

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially...

Confirmed In CISA 30 Nov 2023

Common Vulnerability Classes (CWE)

  • CWE-416 — Use After Free 20
  • CWE-787 — Out-of-bounds Write 19
  • CWE-843 — Access of Resource Using Incompatible Type ('Type Confusion') 19
  • CWE-190 — Integer Overflow or Wraparound 5
  • CWE-125 — Out-of-bounds Read 5
  • CWE-20 — Improper Input Validation 5
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 2
  • CWE-122 — Heap-based Buffer Overflow 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology