target entity

Google

72 source-linked records in the current knowledge graph.

high

CVE-2026-11645: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-11645EPSS 1.7%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2026-5281: Google Dawn Use-After-Free Vulnerability

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-5281EPSS 5.0%DawnGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2026-3910: Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability

Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-3910EPSS 2.0%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2026-3909: Google Skia Out-of-Bounds Write Vulnerability

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-3909EPSS 1.6%GoogleSkia
CISA KEV ↗ · unattributed attribution
high

CVE-2026-2441: Google Chromium CSS Use-After-Free Vulnerability

Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-2441EPSS 22.0%ChromiumGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2025-14174: Google Chromium Out of Bounds Memory Access Vulnerability

Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-14174EPSS 22.7%ChromiumGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2025-13223: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-13223EPSS 4.9%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2025-10585: Google Chromium V8 Type Confusion Vulnerability

Google Chromium contains a type confusion vulnerability in the V8 JavaScript and WebAssembly engine. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-10585EPSS 5.4%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2025-6558: Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-6558EPSS 9.2%ChromiumGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2025-6554: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-6554EPSS 6.6%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2025-5419: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-5419EPSS 6.5%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2025-2783: Google Chromium Mojo Sandbox Escape Vulnerability

Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-2783EPSS 8.4%Chromium MojoGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2024-7965: Google Chromium V8 Inappropriate Implementation Vulnerability

Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-7965EPSS 17.2%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2024-7971: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-7971EPSS 19.3%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2024-5274: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-5274EPSS 10.0%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2024-4947: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-4947EPSS 15.1%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2024-4761: Google Chromium V8 Out-of-Bounds Memory Write Vulnerability

Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-4761EPSS 11.0%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2024-4671: Google Chromium Visuals Use-After-Free Vulnerability

Google Chromium Visuals contains a use-after-free vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-4671EPSS 8.3%ChromiumGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-4762: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-4762EPSS 38.0%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2024-0519: Google Chromium V8 Out-of-Bounds Memory Access Vulnerability

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-0519EPSS 3.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2023-7024: Google Chromium WebRTC Heap Buffer Overflow Vulnerability

Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-7024EPSS 7.4%Chromium WebRTCGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-6345: Google Skia Integer Overflow Vulnerability

Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a malicious file. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-6345EPSS 19.6%Chromium SkiaGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-5217: Google Chromium libvpx Heap Buffer Overflow Vulnerability

Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-5217EPSS 49.0%Chromium libvpxGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-4863: Google Chromium WebP Heap-Based Buffer Overflow Vulnerability

Google Chromium WebP contains a heap-based buffer overflow vulnerability that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. This vulnerability can affect applications that use the WebP Codec. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-4863EPSS 99.7%Chromium WebPGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-3079: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2023-3079EPSS 32.7%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2023-2136: Google Chrome Skia Integer Overflow Vulnerability

Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. Required action: Apply updates per vendor instructions.

CVE-2023-2136EPSS 5.8%Chromium SkiaGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2023-2033: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2023-2033EPSS 40.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2022-3038: Google Chromium Network Service Use-After-Free Vulnerability

Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-3038EPSS 24.7%Chromium Network ServiceGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2022-4262: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-4262EPSS 16.1%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2022-4135: Google Chromium GPU Heap Buffer Overflow Vulnerability

Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-4135EPSS 31.9%Chromium GPUGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2022-3723: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-3723EPSS 6.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2022-3075: Google Chromium Mojo Insufficient Data Validation Vulnerability

Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-3075EPSS 5.7%Chromium MojoGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2022-2856: Google Chromium Intents Insufficient Input Validation Vulnerability

Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-2856EPSS 4.5%Chromium IntentsGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30533: Google Chromium PopupBlocker Security Bypass Vulnerability

Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-30533EPSS 16.6%Chromium PopupBlockerGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2019-5825: Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2019-5825EPSS 55.9%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2018-6065: Google Chromium V8 Integer Overflow Vulnerability

Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2018-6065EPSS 60.3%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2018-17480: Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains out-of-bounds write vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2018-17480EPSS 34.3%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2018-17463: Google Chromium V8 Remote Code Execution Vulnerability

Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2018-17463EPSS 84.6%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2017-5070: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2017-5070EPSS 31.2%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2017-5030: Google Chromium V8 Memory Corruption Vulnerability

Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2017-5030EPSS 41.6%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2016-5198: Google Chromium V8 Out-of-Bounds Memory Vulnerability

Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code execution, via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2016-5198EPSS 34.7%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2016-1646: Google Chromium V8 Out-of-Bounds Read Vulnerability

Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2016-1646EPSS 48.1%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2019-5786: Google Chrome Blink Use-After-Free Vulnerability

Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page. Required action: Apply updates per vendor instructions.

CVE-2019-5786EPSS 61.5%Chrome BlinkGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2022-1364: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-1364EPSS 13.7%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2022-1096: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-1096EPSS 24.2%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2022-0609: Google Chromium Animation Use-After-Free Vulnerability

Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2022-0609EPSS 23.5%Chromium AnimationGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-4102: Google Chromium V8 Use-After-Free Vulnerability

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-4102EPSS 7.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2020-16010: Google Chrome for Android UI Heap Buffer Overflow Vulnerability

Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. Required action: Apply updates per vendor instructions.

CVE-2020-16010EPSS 6.4%Chrome for Android UIGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-15999: Google Chrome FreeType Heap Buffer Overflow Vulnerability

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android. Required action: Apply updates per vendor instructions.

CVE-2020-15999CVE-2020-16010EPSS 50.6%Chrome FreeTypeGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21166: Google Chromium Race Condition Vulnerability

Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-21166EPSS 26.5%ChromiumGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-16017: Google Chrome Use-After-Free Vulnerability

Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. Required action: Apply updates per vendor instructions.

CVE-2020-16017EPSS 2.7%ChromeGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-37976: Google Chromium Information Disclosure Vulnerability

Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-37976EPSS 19.9%ChromiumGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-16009: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2020-16009EPSS 48.6%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30632: Google Chromium V8 Out-of-Bounds Write Vulnerability

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-30632EPSS 64.5%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2020-16013: Google Chromium V8 Incorrect Implementation Vulnerabililty

Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2020-16013EPSS 2.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30633: Google Chromium Indexed DB API Use-After-Free Vulnerability

Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-30633EPSS 32.7%Chromium Indexed DB APIGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21148: Google Chromium V8 Heap Buffer Overflow Vulnerability

Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-21148EPSS 19.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-37973: Google Chromium Portals Use-After-Free Vulnerability

Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge. Required action: Apply updates per vendor instructions.

CVE-2021-37973EPSS 11.7%Chromium PortalsGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30551: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-30551EPSS 64.7%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-37975: Google Chromium V8 Use-After-Free Vulnerability

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-37975EPSS 34.9%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2020-6418: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2020-6418EPSS 78.8%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30554: Google Chromium WebGL Use-After-Free Vulnerability

Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-30554EPSS 7.4%Chromium WebGLGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21206: Google Chromium Blink Use-After-Free Vulnerability

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-21206EPSS 9.4%Chromium BlinkGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-38000: Google Chromium Intents Improper Input Validation Vulnerability

Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-38000EPSS 4.5%Chromium IntentsGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-38003: Google Chromium V8 Memory Corruption Vulnerability

Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-38003EPSS 36.2%Chromium V8Google
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2021-21224: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-21224EPSS 57.7%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21193: Google Chromium Blink Use-After-Free Vulnerability

Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-21193EPSS 9.9%Chromium BlinkGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2021-21220: Google Chromium V8 Improper Input Validation Vulnerability

Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-21220EPSS 70.4%Chromium V8Google
CISA KEV ↗ · unattributed attribution
high

CVE-2021-30563: Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply updates per vendor instructions.

CVE-2021-30563EPSS 8.9%Chromium V8Google
CISA KEV ↗ · unattributed attribution