Filtered by vendor Google
Subscribe
Total
16512 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-76017 | 1 Google | 1 Chrome | 2026-08-25 | N/A | 8.8 HIGH |
| Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical) | |||||
| CVE-2026-76035 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-24 | N/A | 9.6 CRITICAL |
| Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-76039 | 1 Google | 2 Android, Chrome | 2026-08-21 | N/A | 6.5 MEDIUM |
| Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-76040 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-21 | N/A | 8.8 HIGH |
| Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-76041 | 1 Google | 1 Chrome | 2026-08-21 | N/A | 4.3 MEDIUM |
| Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-76042 | 1 Google | 1 Chrome | 2026-08-21 | N/A | 3.1 LOW |
| Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-76043 | 1 Google | 1 Chrome | 2026-08-21 | N/A | 8.8 HIGH |
| Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-76044 | 1 Google | 1 Chrome | 2026-08-21 | N/A | 8.3 HIGH |
| Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-76045 | 1 Google | 1 Chrome | 2026-08-21 | N/A | 8.8 HIGH |
| Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-76046 | 1 Google | 2 Android, Chrome | 2026-08-21 | N/A | 8.3 HIGH |
| Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-8497 | 3 Apple, Devolutions, Google | 4 Iphone Os, Macos, Password Manager and 1 more | 2026-08-21 | N/A | 7.4 HIGH |
| Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate. | |||||
| CVE-2026-76034 | 1 Google | 1 Chrome | 2026-08-20 | N/A | 8.8 HIGH |
| Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |||||
| CVE-2026-76036 | 1 Google | 2 Android, Chrome | 2026-08-20 | N/A | 9.6 CRITICAL |
| Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |||||
| CVE-2026-76037 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-20 | N/A | 8.4 HIGH |
| Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) | |||||
| CVE-2026-76038 | 1 Google | 1 Chrome | 2026-08-20 | N/A | 8.8 HIGH |
| Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-76047 | 1 Google | 1 Chrome | 2026-08-20 | N/A | 8.8 HIGH |
| Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-76033 | 1 Google | 1 Chrome | 2026-08-20 | N/A | 4.2 MEDIUM |
| Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2023-23374 | 2 Google, Microsoft | 2 Android, Edge Chromium | 2026-08-19 | N/A | 8.3 HIGH |
| Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |||||
| CVE-2020-26964 | 2 Google, Mozilla | 2 Android, Firefox Mobile | 2026-08-19 | 4.0 MEDIUM | 6.8 MEDIUM |
| If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however, SELinux was not enforced for versions prior to 6.0. This was fixed by removing the Remote Debugging via USB feature from affected devices. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83. | |||||
| CVE-2026-11717 | 1 Google | 1 Mcp Toolbox For Databases | 2026-08-17 | N/A | 9.1 CRITICAL |
| An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When verifying an unparsed opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), the toolbox decodes the response into an introspectResp struct where the Active field is declared as a pointer to a boolean (*bool). The code only explicitly rejects a token if the response contains a populated active field set to false (if introspectResp.Active != nil && !*introspectResp.Active). If an introspection endpoint responds with a payload that completely omits the mandatory active key, the internal variable remains nil, causing the conditional check to short-circuit. As a result, Toolbox accepts authorization tokens missing the "active" field, granting access to protected tools and underlying data sources. | |||||
