Google vulnerabilities exploited in the wild
The Google CVEs that CISA lists as exploited, newest first. Only confirmed exploitation appears here, each with its EPSS and the CVSS as published.
Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time
- 75
- flaws with confirmed attacks
- 0
- used by ransomware
- 4.3%
- of the whole catalog
12 vulnerabilities · newest first.Showing the entries bundled with this page while the full catalog loads.
- CVE-2026-58704Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Pixel
Google Pixel Improper Authorization Vulnerability
Severity
8.8HIGHCVSS 3.1 · CISA-ADPAttack probability (EPSS)
0.59%46th pctKEV dates
added due - CVE-2026-87491Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Chromium V8
Google Chromium V8 Out of Bounds Write Vulnerability
Severity
8.8HIGHCVSS 3.1 · CISA-ADPAttack probability (EPSS)
3.14%87th pctKEV dates
added due - CVE-2026-85046Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Chromium V8
Google Chromium V8 Type Confusion Vulnerability
Severity
8.8HIGHCVSS 3.1 · CISA-ADPAttack probability (EPSS)
48.9%99th pctKEV dates
added due - CVE-2026-11645Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Chromium V8
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
Severity
8.8HIGHCVSS 3.1 · CISA-ADPAttack probability (EPSS)
2.19%82th pctKEV dates
added due - CVE-2026-5281Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Dawn
Google Dawn Use-After-Free Vulnerability
Severity
8.8HIGHCVSS 3.1 · CISA-ADPAttack probability (EPSS)
0.70%52th pctKEV dates
added due - CVE-2026-3909Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Skia
Google Skia Out-of-Bounds Write Vulnerability
Severity
8.8HIGHCVSS 3.1 · NVDAttack probability (EPSS)
2.30%83th pctKEV dates
added due - CVE-2026-3910Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Chromium V8
Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability
Severity
8.8HIGHCVSS 3.1 · NVDAttack probability (EPSS)
1.03%62th pctKEV dates
added due - CVE-2026-2441Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Chromium
Google Chromium CSS Use-After-Free Vulnerability
Severity
8.8HIGHCVSS 3.1 · NVDAttack probability (EPSS)
55.1%99.0th pctKEV dates
added due - CVE-2025-14174Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Chromium
Google Chromium Out of Bounds Memory Access Vulnerability
Severity
8.8HIGHCVSS 3.1 · CISA-ADPAttack probability (EPSS)
22.3%98th pctKEV dates
added due - CVE-2025-13223Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Chromium V8
Google Chromium V8 Type Confusion Vulnerability
Severity
8.8HIGHCVSS 3.1 · CISA-ADPAttack probability (EPSS)
5.03%92th pctKEV dates
added due - CVE-2025-10585Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Chromium V8
Google Chromium V8 Type Confusion Vulnerability
Severity
9.8CRITICALCVSS 3.1 · NVDAttack probability (EPSS)
5.39%92th pctKEV dates
added due - CVE-2025-6558Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog
Google · Chromium
Google Chromium ANGLE and GPU Improper Input Validation Vulnerability
Severity
8.8HIGHCVSS 3.1 · CISA-ADPAttack probability (EPSS)
9.59%95th pctKEV dates
added due
Google products in the catalog
Among the most recent entries, the products that appear most often are:
- Chromium V86 entries
- Chromium3 entries
- Pixel1 entry
- Dawn1 entry
- Skia1 entry
Product names are the ones CISA uses in the catalog. To check a specific Google CVE that is not on this page, use the CVE lookup: it shows the record, the affected versions and the EPSS score even when the CVE is not in KEV.
Fixed versions and workarounds are published by the vendor: Chrome Releases (Google).
Other vendors
- Microsoft389exploited · 117 in ransomware
- Cisco100exploited · 7 in ransomware
- Apple95exploited · 0 in ransomware
- Adobe82exploited · 11 in ransomware
- Oracle46exploited · 13 in ransomware
- Apache40exploited · 8 in ransomware
- Ivanti35exploited · 12 in ransomware
- Fortinet31exploited · 14 in ransomware
- Linux31exploited · 2 in ransomware
- Citrix26exploited · 7 in ransomware
- D-Link26exploited · 2 in ransomware
Questions
How many Google vulnerabilities are known to be exploited?
The CISA KEV catalog, version 2026.10.02, lists 75 Google vulnerabilities as of 3 Oct 2026. CISA marks 0 of them as known to be used in ransomware campaigns.
What is the most recent Google entry in KEV?
CVE-2026-58704 (Google Pixel Improper Authorization Vulnerability), added on 16 Sep 2026 with a due date of 19 Sep 2026 for US federal agencies, as of the collection of 3 Oct 2026.
Does this page list every Google CVE?
No. It lists only the Google CVEs that CISA has confirmed as exploited. Google publishes many more CVEs that are not in KEV; look up any of them by identifier in the CVE lookup to see its record and EPSS score.
In what order should Google vulnerabilities be patched?
Everything on this page is already confirmed as exploited, so all of it is urgent where the product is in use. Within the list, entries marked with known ransomware use and those with the highest EPSS come first in the "Risk" order; internet-facing systems should go before internal ones.
Related sections
- WatchlistWhat attackers started using this month, most urgent first.
- Exploited catalogEvery flaw CISA lists as used in real attacks (KEV), searchable.
- CVE lookupType one identifier: attack status, probability, severity, versions.
- Attack probabilityEPSS score for up to 100 identifiers at once.
- VendorsWhich vendors have the most exploited flaws.
- RSS and JSON feedsFollow new exploited flaws for the vendors you run.
- Sources and methodWhere each number comes from and how the order is decided.