Google-inc
529 CVEs tracked since 2017. Since Feb 2017, none of them reached CISA KEV.
Google-inc CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2017-02 | 54 | 0 |
| 2017-03 | 83 | 0 |
| 2017-04 | null or fewer | |
| 2017-05 | 70 | 0 |
| 2017-06 | null or fewer | |
| 2017-07 | 46 | 0 |
| 2017-08 | 36 | 0 |
| 2017-09 | 52 | 0 |
| 2017-10 | 22 | 0 |
| 2017-11 | null or fewer | |
| 2017-12 | 38 | 0 |
| 2018-01 | 51 | 0 |
| 2018-02 | 20 | 0 |
| 2018-03 | null or fewer | |
| 2018-04 | null or fewer | |
| 2018-05 | null or fewer | |
| 2018-06 | null or fewer | |
| 2018-07 | null or fewer | |
| 2018-08 | null or fewer | |
| 2018-09 | null or fewer | |
| 2018-10 | 25 | 0 |
| 2018-11 | null or fewer | |
| 2018-12 | 32 | 0 |
Products
The products that kept showing up in Google-inc's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Google-inc.
- CVE-2025-48617In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution...7.8
- CVE-2026-1220Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)7.5
- CVE-2026-11701Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)5.4
- CVE-2026-11700Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page...8.3
- CVE-2026-11645Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity...8.8
- CVE-2026-11236Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v...8.3
- CVE-2026-11237Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted H...8.3
- CVE-2026-11235Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox ...8.8
- CVE-2026-11233Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted...4.7
- CVE-2026-11232Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)5.4
- CVE-2026-11231Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)8.1
- CVE-2026-11230Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)8.8
- CVE-2026-11229Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security sev...6.1
- CVE-2026-11228Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a craf...4.3
- CVE-2026-11227Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)6.5
The record
- Peak rank
- #3 in May 2017
- Busiest month shown
- Mar 2017, 83 CVEs
- Months with a KEV entry
- 0 since Feb 2017
- Monthly snapshots
- 12 since 2017