Google security briefs
11 published alerts for Google products and services.
Google Pixel Improper Authorization Vulnerability
Google Pixel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-58704). Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. CISA remediation due date: 2026-09-19. If you need help checking exposure, call (864) 335-9223.
Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-87491). Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CISA remediation due date: 2026-09-23. If you need help checking exposure, call (864) 335-9223.
Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-85046). Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CISA remediation due date: 2026-09-18. If you need help checking exposure, call (864) 335-9223.
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Google Chromium V8 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-11645). Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CISA remediation due date: 2026-06-23. If you need help checking exposure, call (864) 335-9223.
Google Dawn Use-After-Free Vulnerability
Google Dawn is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-5281). Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CISA remediation due date: 2026-04-15. If you need help checking exposure, call (864) 335-9223.
Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability
Google Chromium V8 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-3910). Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CISA remediation due date: 2026-03-27. If you need help checking exposure, call (864) 335-9223.
Google Skia Out-of-Bounds Write Vulnerability
Google Skia is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-3909). Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. CISA remediation due date: 2026-03-27. If you need help checking exposure, call (864) 335-9223.
Google Chromium CSS Use-After-Free Vulnerability
Google Chromium is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-2441). Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CISA remediation due date: 2026-03-10. If you need help checking exposure, call (864) 335-9223.
Google Chromium Out of Bounds Memory Access Vulnerability
Google Chromium is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-14174). Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. CISA remediation due date: 2026-01-02. If you need help checking exposure, call (864) 335-9223.
Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-13223). Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption. CISA remediation due date: 2025-12-10. If you need help checking exposure, call (864) 335-9223.
Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-10585). Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine. CISA remediation due date: 2025-10-14. If you need help checking exposure, call (864) 335-9223.