CVE Tools

Google

14,382 CVEs tracked since 2003. Since Sep 2021, 68 of them reached CISA KEV.

Google CVEs per month

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Google CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-09390
2021-101115
2021-11952
2021-121972
2022-01631
2022-021721
2022-031372
2022-041361
2022-05880
2022-061210
2022-071993
2022-082210
2022-091863
2022-10990
2022-111372
2022-122701
2023-011120
2023-021060
2023-03null or fewer
2023-041012
2023-051390
2023-061692
2023-071460
2023-081440
2023-091374
2023-102051
2023-11751
2023-121981
2024-01611
2024-02690
2024-03920
2024-04792
2024-05574
2024-06821
2024-07750
2024-08652
2024-09600
2024-10780
2024-111362
2024-12641
2025-011050
2025-02470
2025-03351
2025-04270
2025-05290
2025-06212
2025-07231
2025-08510
2025-091864
2025-10170
2025-11771
2025-121333
2026-01450
2026-02351
2026-031782
2026-041471
2026-053800
2026-0610952
2026-074960
2026-084020
2026-095163

Products

The products that kept showing up in Google's monthly top three, with their CVEs summed over those months.

  1. Android4,26757 months
  2. Chrome3,92052 months
  3. Google Chrome1,49551 months
  4. Tensorflow1734 months
  5. Android Studio173 months
  6. Chrome OS81 month
  7. Kubernetes51 month
  8. Mcp-toolbox51 month
  9. Fuchsia21 month
  10. Mcp Toolbox For Databases (Googleapis/mcp-toolbox)21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Google.

  1. CVE-2026-96812Host Root Sandbox Escape in gVisor via Character Device Passthrough and CUSE—
  2. CVE-2026-19202Token Cache Reuse in mcp-toolbox-sdk-python—
  3. CVE-2026-93386UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium securi...5.4
  4. CVE-2026-93385Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)6.5
  5. CVE-2026-93378Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromiu...3.1
  6. CVE-2026-93377Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium ...8.8
  7. CVE-2026-93384Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted...3.7
  8. CVE-2026-93380Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access rest...3.1
  9. CVE-2026-93383Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)4.3
  10. CVE-2026-93376Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium s...6.3
  11. CVE-2026-93387Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)4.3
  12. CVE-2026-93381Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via ...8.8
  13. CVE-2026-93373Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security sever...9.6
  14. CVE-2026-93379Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)4.3
  15. CVE-2026-93375Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local progra...8.1

The record

Peak rank
#1 in Jun 2026
Busiest month shown
Jun 2026, 1,095 CVEs
Months with a KEV entry
35 since Sep 2021
Monthly snapshots
205 since 2003
Google's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store