Google Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Google products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

90

In CISA KEV

90

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Google KEVs Added by Year

Loading...

90 Google KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2023-7024

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a...

Confirmed In CISA 02 Jan 2024
CVE-2024-0519

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a...

Confirmed In CISA 17 Jan 2024
CVE-2023-4762

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page....

Confirmed In CISA 06 Feb 2024
CVE-2023-21237

In applyRemoteView of NotificationContentInflater.java, there is a possible way to hide foreground service notification due to misleading or...

Confirmed In CISA 05 Mar 2024
CVE-2024-29745

there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution...

Confirmed In CISA 04 Apr 2024
CVE-2024-29748

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution...

Confirmed In CISA 04 Apr 2024
CVE-2024-4671

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to...

Confirmed In CISA 13 May 2024
CVE-2024-4761

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted...

Confirmed In CISA 16 May 2024
CVE-2024-4947

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted...

Confirmed In CISA 20 May 2024
CVE-2024-5274

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted...

Confirmed In CISA 28 May 2024
CVE-2024-32896

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution...

Confirmed In CISA 13 Jun 2024
CVE-2024-7971

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page....

Confirmed In CISA 26 Aug 2024
CVE-2024-7965

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a...

Confirmed In CISA 28 Aug 2024
CVE-2024-43093

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive...

Confirmed In CISA 07 Nov 2024
CVE-2025-2783

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to...

Confirmed In CISA 27 Mar 2025

Common Vulnerability Classes (CWE)

  • CWE-416 — Use After Free 20
  • CWE-787 — Out-of-bounds Write 19
  • CWE-843 — Access of Resource Using Incompatible Type ('Type Confusion') 19
  • CWE-190 — Integer Overflow or Wraparound 5
  • CWE-125 — Out-of-bounds Read 5
  • CWE-20 — Improper Input Validation 5
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 2
  • CWE-122 — Heap-based Buffer Overflow 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology