14,382 CVEs tracked since 2003. Since Sep 2021, 68 of them reached CISA KEV.
Google CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-09 | 39 | 0 |
| 2021-10 | 111 | 5 |
| 2021-11 | 95 | 2 |
| 2021-12 | 197 | 2 |
| 2022-01 | 63 | 1 |
| 2022-02 | 172 | 1 |
| 2022-03 | 137 | 2 |
| 2022-04 | 136 | 1 |
| 2022-05 | 88 | 0 |
| 2022-06 | 121 | 0 |
| 2022-07 | 199 | 3 |
| 2022-08 | 221 | 0 |
| 2022-09 | 186 | 3 |
| 2022-10 | 99 | 0 |
| 2022-11 | 137 | 2 |
| 2022-12 | 270 | 1 |
| 2023-01 | 112 | 0 |
| 2023-02 | 106 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 101 | 2 |
| 2023-05 | 139 | 0 |
| 2023-06 | 169 | 2 |
| 2023-07 | 146 | 0 |
| 2023-08 | 144 | 0 |
| 2023-09 | 137 | 4 |
| 2023-10 | 205 | 1 |
| 2023-11 | 75 | 1 |
| 2023-12 | 198 | 1 |
| 2024-01 | 61 | 1 |
| 2024-02 | 69 | 0 |
| 2024-03 | 92 | 0 |
| 2024-04 | 79 | 2 |
| 2024-05 | 57 | 4 |
| 2024-06 | 82 | 1 |
| 2024-07 | 75 | 0 |
| 2024-08 | 65 | 2 |
| 2024-09 | 60 | 0 |
| 2024-10 | 78 | 0 |
| 2024-11 | 136 | 2 |
| 2024-12 | 64 | 1 |
| 2025-01 | 105 | 0 |
| 2025-02 | 47 | 0 |
| 2025-03 | 35 | 1 |
| 2025-04 | 27 | 0 |
| 2025-05 | 29 | 0 |
| 2025-06 | 21 | 2 |
| 2025-07 | 23 | 1 |
| 2025-08 | 51 | 0 |
| 2025-09 | 186 | 4 |
| 2025-10 | 17 | 0 |
| 2025-11 | 77 | 1 |
| 2025-12 | 133 | 3 |
| 2026-01 | 45 | 0 |
| 2026-02 | 35 | 1 |
| 2026-03 | 178 | 2 |
| 2026-04 | 147 | 1 |
| 2026-05 | 380 | 0 |
| 2026-06 | 1095 | 2 |
| 2026-07 | 496 | 0 |
| 2026-08 | 402 | 0 |
| 2026-09 | 516 | 3 |
Products
The products that kept showing up in Google's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Google.
- CVE-2026-96812Host Root Sandbox Escape in gVisor via Character Device Passthrough and CUSE—
- CVE-2026-19202Token Cache Reuse in mcp-toolbox-sdk-python—
- CVE-2026-93386UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium securi...5.4
- CVE-2026-93385Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)6.5
- CVE-2026-93378Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromiu...3.1
- CVE-2026-93377Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium ...8.8
- CVE-2026-93384Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted...3.7
- CVE-2026-93380Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access rest...3.1
- CVE-2026-93383Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)4.3
- CVE-2026-93376Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium s...6.3
- CVE-2026-93387Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)4.3
- CVE-2026-93381Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via ...8.8
- CVE-2026-93373Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security sever...9.6
- CVE-2026-93379Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)4.3
- CVE-2026-93375Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local progra...8.1
The record
- Peak rank
- #1 in Jun 2026
- Busiest month shown
- Jun 2026, 1,095 CVEs
- Months with a KEV entry
- 35 since Sep 2021
- Monthly snapshots
- 205 since 2003