By vendor

Google vulnerabilities

Known CVEs affecting Google products, prioritized by severity, with SEC.co remediation and detection guidance.

1195 published vulnerabilities · page 5 of 12

  • CVE-2026-9905HIGH 8.3

    A use-after-free vulnerability exists in Google Chrome's accessibility features on Windows. An attacker who has already compromised Chrome's renderer process can exploit this flaw through a specially crafted HTML page to break out of Chrome's sandbox and gain system-level access. This is a post-compromise risk: the attacker must first have control of the renderer, but if they do, this vulnerability provides a direct path to escape Chrome's security isolation and potentially take full control of your computer.

  • CVE-2026-9906HIGH 8.3

    Google Chrome versions prior to 148.0.7778.216 contain a memory safety flaw in GPU processing that could allow an attacker with control of the browser's renderer process to break out of the sandbox and gain system-level access. The attack requires the renderer to already be compromised and the user to visit a malicious webpage, but success would bypass Chrome's primary security boundary.

  • CVE-2026-9914HIGH 8.3

    An attacker who gains control of Chrome's rendering engine can use this vulnerability to break out of the browser sandbox by crafting a malicious webpage. The flaw stems from inadequate validation of untrusted data within ANGLE, a graphics abstraction layer, allowing an attacker to execute code with privileges beyond the sandbox constraints.

  • CVE-2026-9915HIGH 8.3

    A heap buffer overflow vulnerability exists in ANGLE, the graphics abstraction layer used by Google Chrome, affecting versions prior to 148.0.7778.216. An attacker who has already compromised Chrome's renderer process can exploit this flaw via a specially crafted HTML page to potentially escape the browser sandbox and gain elevated privileges on the system. This requires the attacker to first compromise the renderer, making it a post-compromise threat rather than a direct entry point.

  • CVE-2026-9916HIGH 8.3

    A memory safety flaw exists in the ANGLE graphics library component of Google Chrome. An attacker who has already compromised the browser's renderer process could exploit this out-of-bounds write to break out of the browser sandbox and gain system-level access. Exploitation requires the attacker to deliver a crafted HTML page and needs user interaction to trigger. The vulnerability affects Chrome versions before 148.0.7778.216.

  • CVE-2026-9924HIGH 8.3

    A flaw in the ANGLE graphics library (which Chrome uses to render graphics on Windows) can cause memory corruption when processing specially crafted web content. An attacker who has already compromised Chrome's sandboxed renderer process could exploit this to escape the sandbox and gain full system access. The vulnerability requires user interaction—the victim must open a malicious webpage—but once the renderer is compromised, the attacker has a path to execute code outside the sandbox.

  • CVE-2026-9925HIGH 8.3

    A use-after-free flaw in ANGLE (the graphics abstraction layer used by Google Chrome) can allow an attacker to escape the browser sandbox if they first compromise the renderer process. The attacker would craft a malicious HTML page to trigger memory corruption that leads to code execution outside the sandbox boundary. This requires two conditions: initial renderer compromise and user interaction with the hostile page.

  • CVE-2026-9926HIGH 8.3

    A memory error in Chrome's graphics processing component (ANGLE) could allow an attacker who has already compromised the renderer process to break out of the sandbox and access the wider system. The vulnerability requires the attacker to deliver a specially crafted webpage and the user to interact with it, but once triggered, it could lead to full system compromise. The issue affects Chrome versions prior to 148.0.7778.216.

  • CVE-2026-9931HIGH 8.3

    A use-after-free memory flaw in Chrome's GPU component allows an attacker who has already compromised the browser's renderer process to break out of Chrome's sandbox and gain system-level access. The attacker would need to trick a user into visiting a malicious webpage while the renderer is already under attack. This is a post-compromise privilege escalation path rather than a direct remote attack vector.

  • CVE-2026-9932HIGH 8.3

    A use-after-free vulnerability exists in the ANGLE graphics library within Google Chrome on Windows. An attacker who has already compromised Chrome's renderer process can exploit this flaw via a specially crafted HTML page to break out of Chrome's sandbox and gain full system access. This is a chained attack: the initial compromise must occur first, but once inside the renderer, the attacker gains significant additional capabilities.

  • CVE-2026-9936HIGH 8.3

    A use-after-free vulnerability in Google Chrome's graphics rendering engine (GFX) affects Mac systems running versions prior to 148.0.7778.216. The flaw allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox through a malicious HTML page, potentially gaining access to the underlying operating system. This is a post-compromise attack requiring the renderer to already be under attacker control.

  • CVE-2026-9937HIGH 8.3

    A use-after-free flaw in Google Chrome's user interface on Windows allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox and gain system-level access. The attacker would need to craft a malicious HTML page to trigger the vulnerability. This is a critical privilege escalation path because sandbox escapes turn browser compromises into full system compromises.

  • CVE-2026-9946HIGH 8.3

    A use-after-free vulnerability in Google Chrome's ANGLE graphics library could allow an attacker who has already compromised the browser's renderer process to break out of Chrome's security sandbox and execute code with system-level privileges. The flaw affects Chrome versions before 148.0.7778.216 and requires user interaction—typically visiting a malicious website—to trigger the vulnerability chain.

  • CVE-2026-9948HIGH 8.3

    Google Chrome on macOS contains a use-after-free vulnerability in its Views component that could allow an attacker to escape the browser's sandbox. The attack requires two conditions: the attacker must first compromise Chrome's renderer process (the sandboxed component that executes web content), and the victim must interact with a specially crafted webpage. If successful, the attacker gains access beyond the sandbox, potentially compromising the entire system. This vulnerability affects Chrome versions prior to 148.0.7778.216 on macOS.

  • CVE-2026-9949HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome's Core component on Windows that could allow an attacker to escape the browser's sandbox. The vulnerability requires the attacker to have already compromised Chrome's renderer process and trick a user into visiting a malicious webpage. If successfully exploited, an attacker could gain the same privileges as the Windows user running Chrome, potentially compromising the entire system.

  • CVE-2026-9951HIGH 8.3

    Google Chrome before version 148.0.7778.216 contains a use-after-free vulnerability in its user interface rendering engine. This flaw allows an attacker to craft a malicious HTML page that, when visited by a user, can trigger memory corruption. The vulnerability is particularly dangerous because it may enable attackers to break out of Chrome's sandbox—the security boundary that isolates the browser from the underlying operating system—potentially gaining direct access to system resources and user data. Exploitation requires user interaction (clicking or visiting a malicious site) and involves complex attack conditions, but the potential for sandbox escape elevates the risk significantly.

  • CVE-2026-9966HIGH 8.3

    This vulnerability is an integer overflow flaw in how Google Chrome handles XML content on Windows systems. An attacker who has already compromised Chrome's rendering engine could craft a malicious HTML page to escape Chrome's security sandbox—the isolated environment that prevents malicious code from accessing your system directly. The vulnerability requires the attacker to have control of the renderer process first, and it requires user interaction (visiting a malicious page), but if exploited successfully, it could lead to complete system compromise.

  • CVE-2026-9970HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome's WebGL component that could allow an attacker to escape the browser sandbox. An attacker would first need to compromise Chrome's renderer process—typically through a separate exploit or social engineering—and then could use a specially crafted HTML page to gain unauthorized access outside the browser's security boundaries. This vulnerability affects Chrome versions before 148.0.7778.216 on Windows, macOS, and Linux systems.

  • CVE-2026-9972HIGH 8.3

    A vulnerability in Google Chrome on macOS could allow an attacker to escape the browser's security sandbox if the attacker has already compromised Chrome's renderer process. The flaw stems from uninitialized memory in the gamepad handling code. An attacker would need to trick a user into visiting a malicious website while Chrome is running, and would require a prior compromise of the renderer—a critical prerequisite that significantly limits real-world exploitation scenarios. Once exploited, the attacker could potentially gain full system access beyond Chrome's normal restrictions.

  • CVE-2026-9974HIGH 8.3

    CVE-2026-9974 is a memory safety bug in Google Chrome's GPU rendering component that can allow an attacker to escape the browser's sandbox if they first compromise the renderer process. The vulnerability stems from an out-of-bounds write operation, meaning the code writes data outside its intended memory boundaries. An attacker would need to trick a user into visiting a malicious webpage while already having control of Chrome's renderer, making this a secondary exploit that amplifies damage from other browser compromises.

  • CVE-2026-9975HIGH 8.3

    A memory safety vulnerability in Google Chrome's ANGLE graphics library allows an attacker who has already compromised the browser's renderer process to break out of Chrome's sandbox and gain full system access. The flaw involves reading and writing memory beyond intended boundaries, creating a bridge from the restricted renderer environment to the host operating system. This requires the attacker to first successfully compromise the renderer (through a separate browser exploit or vulnerability) and then craft a malicious HTML page to trigger the escape.

  • CVE-2026-9977HIGH 8.3

    A validation flaw in Chrome's WebShare feature on Android allows an attacker who has already compromised Chrome's renderer process to escape the browser sandbox through a specially crafted HTML page. The vulnerability requires the attacker to have gained initial access to the renderer—typically through a separate exploit or compromise—but once inside, the insufficient input checking creates a pathway to break out of the browser's security boundary and potentially gain full device access.

  • CVE-2026-9982HIGH 8.3

    CVE-2026-9982 is a sandbox escape vulnerability in Google Chrome's ANGLE graphics library. An attacker who has already compromised the browser's renderer process can exploit insufficient input validation to break out of the sandbox and gain system-level access. This requires an attacker to first deliver a malicious webpage that triggers the rendering flaw, making it a chained attack scenario rather than a one-step exploitation path.

  • CVE-2026-9988HIGH 8.3

    A use-after-free memory flaw in Chrome's WebRTC component on Linux could allow an attacker to escape the browser's security sandbox. By crafting a malicious webpage, an attacker who tricks a user into visiting it could potentially break out of Chrome's isolation protections and execute code with system-level privileges. This affects Chrome versions before 148.0.7778.216 on Linux systems.

  • CVE-2026-9993HIGH 8.3

    A use-after-free memory vulnerability exists in Google Chrome's rendering engine that allows an attacker to escape the browser's sandbox if they have already compromised the renderer process. The vulnerability is triggered when a user opens a malicious PDF file. This is a critical threat because it could allow an attacker who has gained code execution within the browser to break out of Chrome's security boundaries and gain access to the underlying operating system.

  • CVE-2026-9994HIGH 8.3

    A use-after-free vulnerability exists in Google Chrome's core rendering engine on Windows systems. An attacker who has already compromised the browser's renderer process can exploit this flaw through a specially crafted HTML page to escape the browser sandbox—breaking out of Chrome's security isolation layer. This means an attacker could potentially gain full system access from within the constrained renderer environment.

  • CVE-2026-9997HIGH 8.3

    Google Chrome versions prior to 148.0.7778.216 contain a use-after-free vulnerability in the Input component that could allow an attacker to escape the browser's sandbox. The attack requires the attacker to have already compromised Chrome's renderer process and trick a user into visiting a malicious HTML page. If successful, the attacker could break out of the sandbox and gain access to the underlying operating system.

  • CVE-2026-9998HIGH 8.3

    CVE-2026-9998 is a high-severity integer overflow vulnerability in Google Chrome's Skia graphics library that could allow an attacker to escape the browser's sandbox—a critical security boundary—if they first compromise Chrome's renderer process. The vulnerability requires a specially crafted HTML page and user interaction, making it a significant but not trivial threat. The issue affects Chrome versions before 148.0.7778.216.

  • CVE-2026-10887HIGH 8.1

    A use-after-free flaw in Chrome's Chromoting remote desktop feature on macOS allows attackers to execute arbitrary code by sending specially crafted network traffic. The vulnerability exists in versions prior to 149.0.7827.53 and requires no user interaction—an attacker on the network can trigger the bug remotely, making this a critical threat to any Mac user running an affected Chrome version.

  • CVE-2026-10930HIGH 8.1

    An out-of-bounds read vulnerability in ANGLE (the graphics translation layer used by Chrome on macOS) allows attackers to read sensitive memory from your system by tricking you into visiting a malicious website. The flaw affects Chrome versions before 149.0.7827.53 on Apple macOS. While the attacker cannot directly modify data or take control of your system through this specific vulnerability, they can extract confidential information—including passwords, encryption keys, or other sensitive data stored in memory—and cause Chrome to crash.

  • CVE-2026-11011HIGH 8.1

    A flaw in Google Chrome's Password Manager allows an attacker who has already compromised the browser's renderer process to sidestep site isolation—a critical security boundary that prevents one website from accessing data belonging to another. By crafting a malicious HTML page, the attacker could potentially access sensitive information across different sites. This vulnerability affects Chrome versions before 149.0.7827.53 and requires the attacker to first gain control of the renderer process, which typically happens through a separate exploit or malicious website.

  • CVE-2026-11015HIGH 8.1

    A memory reading flaw in Google Chrome's WebGPU component allows attackers to read data outside the intended memory boundaries when a user visits a specially crafted website. The vulnerability requires user interaction (visiting a malicious page) but does not require special privileges, and while the attacker cannot modify data or directly crash the browser, they can extract sensitive information from the process's memory—such as passwords, keys, or other confidential data stored there.

  • CVE-2026-11111HIGH 8.1

    A memory reading vulnerability exists in Chrome's graphics engine (ANGLE) that allows attackers to access out-of-bounds data on a victim's system. An attacker could craft a malicious webpage that, when visited, leaks sensitive information from the browser's memory without modifying or corrupting system data. This affects Chrome versions prior to 149.0.7827.53. The vulnerability requires user interaction—a person must visit the malicious page—but once there, the attacker gains read access to protected memory regions.

  • CVE-2026-11169HIGH 8.1

    Google Chrome versions before 149.0.7827.53 contain a flaw in how they process XML files that allows attackers to inject malicious scripts or HTML content into a webpage, even when normal security protections should prevent it. An attacker would need to trick a user into opening a specially crafted XML file, but once successful, the injected code can execute with the same privileges as the user, potentially stealing data or taking other harmful actions. The vulnerability affects Chrome on Windows, macOS, and Linux systems.

  • CVE-2026-11170HIGH 8.1

    Google Chrome on Linux contains a vulnerability in its Chromoting feature (the remote desktop capability) that allows an attacker on the network to gain administrative privileges on your system without needing to interact with you. The vulnerability exists in Chrome versions before 149.0.7827.53. While the Chromium project rates this as medium severity, the actual impact—unauthenticated remote privilege escalation—warrants a CVSS score of 8.1 (HIGH), reflecting the seriousness for Linux desktop environments where Chromoting might be enabled.

  • CVE-2026-11185HIGH 8.1

    A use-after-free flaw in the V8 JavaScript engine affects Google Chrome versions before 149.0.7827.53. The vulnerability requires an attacker to trick a user into installing a malicious Chrome extension, which can then execute arbitrary code within the browser's sandbox. While the Chromium project rated this as Medium severity, the CVSS score of 8.1 reflects the high potential impact on confidentiality and integrity. This is a memory safety issue that leverages social engineering to gain code execution capabilities.

  • CVE-2026-11224HIGH 8.1

    A use-after-free vulnerability in Google Chrome's Chromoting remote desktop feature on Linux systems can allow an attacker to execute arbitrary code on a victim's machine through specially crafted network traffic. The attacker does not need any special privileges or user interaction beyond network access. This is a critical flaw in the remote desktop protocol handling that leaves systems open to full code execution compromise.

  • CVE-2026-11231HIGH 8.1

    Google Chrome on macOS contains a flaw in its Safe Browsing feature that could allow an attacker to run malicious code on a user's computer. The vulnerability requires user interaction—specifically, the user must open or interact with a malicious file. While Chromium's security team classified the underlying issue as low severity, the CVSS score of 8.1 reflects the real-world impact: an attacker gaining code execution on the system. This affects Chrome versions prior to 149.0.7827.53 on macOS.

  • CVE-2026-11643HIGH 8.1

    A use-after-free vulnerability exists in Google Chrome's Proxy component that could allow attackers to execute arbitrary code on victim machines through specially crafted network traffic. The flaw affects Chrome versions prior to 149.0.7827.103 and has been rated as Critical by the Chromium security team. While no active exploitation has been confirmed in the wild, the vulnerability's remote nature and code execution potential make it a significant threat requiring prompt patching.

  • CVE-2026-11689HIGH 8.1

    A vulnerability in Google Chrome versions before 149.0.7827.103 allows an attacker who has already compromised Chrome's renderer process to break through site isolation—Chrome's security boundary that keeps websites from accessing each other's data. An attacker would need to trick a user into visiting a malicious webpage after the renderer is already compromised, but if successful, they could read or modify sensitive information across different websites.

  • CVE-2026-11693HIGH 8.1

    Google Chrome versions before 149.0.7827.103 contain a flaw in how plugins are handled that allows a remote attacker to break through Chrome's site isolation security boundary. Site isolation is Chrome's defense mechanism that keeps different websites in separate processes to prevent one compromised site from accessing data from another. An attacker who has already compromised the renderer process—the part of Chrome that executes web pages—can craft a malicious HTML page to bypass this isolation, potentially gaining unauthorized access to sensitive data from other open websites or sessions.

  • CVE-2026-12012HIGH 8.1

    Google Chrome contains a use-after-free flaw in its network handling code that could allow attackers on a privileged network position to corrupt Chrome's memory and potentially execute code. The vulnerability affects Chrome versions before 149.0.7827.115 and is rated High severity. An attacker would need both network access and the ability to intercept or manipulate traffic, but would not need user interaction to trigger the flaw.

  • CVE-2026-13774HIGH 8.1

    A use-after-free memory vulnerability exists in Google Chrome's extension handling mechanism. An attacker can exploit this by tricking a user into installing a malicious Chrome extension, which could then execute arbitrary code with the privileges of the Chrome browser. The vulnerability affects Chrome versions before 150.0.7871.47 and is rated as high-severity by CVSS standards, though Google classifies the underlying issue as critical from a Chromium perspective.

  • CVE-2026-13779HIGH 8.1

    A use-after-free memory vulnerability exists in Chrome's remote desktop (Chromoting) feature on ChromeOS. An attacker sending specially crafted network traffic could trigger this flaw to run arbitrary code on a victim's device. The vulnerability affects Chrome on ChromeOS versions prior to 150.0.7871.47 and carries Google's Critical severity rating.

  • CVE-2026-13787HIGH 8.1

    A use-after-free vulnerability exists in Google Chrome's Chromoting feature (remote desktop functionality) on Windows systems. The flaw allows an attacker to send specially crafted network traffic that causes Chrome to use memory that has already been freed, potentially leading to arbitrary code execution. This is a remote attack that requires no user interaction beyond having Chrome running, though specific network conditions must align for exploitation to succeed.

  • CVE-2026-13791HIGH 8.1

    CVE-2026-13791 is a code execution vulnerability in Google Chrome's download handling system that affects versions prior to 150.0.7871.47. The flaw stems from insufficient validation of user-supplied input when processing malicious Chrome extensions. An attacker must first convince a user to install a specially crafted extension, but once installed, the extension can execute arbitrary code with the privileges of the Chrome process. This represents a post-installation code execution risk rather than a browser compromise via web browsing alone.

  • CVE-2026-13799HIGH 8.1

    A use-after-free defect in Google Chrome's QUIC protocol implementation allows attackers to trigger memory corruption by sending specially crafted network packets. An attacker can exploit this remotely without user interaction or special privileges. While the vulnerability requires specific network conditions to trigger (reflected in the CVSS complexity score), successful exploitation could enable arbitrary code execution on affected systems.

  • CVE-2026-13806HIGH 8.1

    Google Chrome versions before 150.0.7871.47 contain a vulnerability in its Accessibility feature that allows an attacker to break out of the browser's site isolation sandbox. Site isolation is Chrome's defense mechanism that keeps different websites in separate processes so that a compromised website cannot steal data from other sites. This vulnerability requires two conditions: the attacker must first compromise the renderer process (the part of Chrome that runs website code), and the user must visit a malicious HTML page. If both occur, the attacker can bypass site isolation to access data from other open websites.

  • CVE-2026-13819HIGH 8.1

    A memory-reading vulnerability exists in the ANGLE graphics library within Google Chrome on macOS versions prior to 150.0.7871.47. An attacker who has already compromised Chrome's renderer process can craft a malicious web page to read data from outside the intended memory boundaries, potentially exposing sensitive information. The vulnerability requires the attacker to have already gained control of the renderer process, which typically happens after successful exploitation of another Chrome vulnerability.

  • CVE-2026-13864HIGH 8.1

    A flaw in Google Chrome's WebHID (Web Hardware Interface Device) policy enforcement allows attackers to escalate their privileges if they can trick a user into installing a malicious browser extension. While the attack requires social engineering—convincing someone to install the extension—the underlying technical weakness is significant because it bypasses Chrome's normally strict security boundaries around hardware access. Once installed, the extension gains the ability to interact with USB and other hardware devices in ways that shouldn't be possible, effectively elevating its capabilities beyond what the user intended to grant.

  • CVE-2026-13974HIGH 8.1

    Google Chrome on macOS contains an integer overflow flaw in its Safe Browsing feature that allows an attacker to bypass navigation restrictions through a malicious file. The vulnerability requires user interaction—specifically, the user must open or download a malicious file—but once triggered, it can lead to integrity compromise and availability impact. This affects Chrome versions prior to 150.0.7871.47 on macOS systems.

  • CVE-2026-14011HIGH 8.1

    Google Chrome versions prior to 150.0.7871.47 contain an out-of-bounds read vulnerability in the SurfaceCapture component. An attacker can exploit this flaw by crafting a malicious HTML page that, when visited by a user, triggers an out-of-bounds memory read. While the Chromium team classified this as Medium severity internally, the CVSS 3.1 score of 8.1 reflects the high practical risk: an attacker gains unauthorized access to sensitive memory contents without requiring special privileges, and the vulnerability impacts both confidentiality and availability.

  • CVE-2026-14032HIGH 8.1

    A use-after-free memory vulnerability exists in the Bluetooth implementation of Google Chrome on macOS. An attacker could exploit this by convincing a user to install a malicious Chrome extension, which could then execute arbitrary code with the privileges of the browser. While the Chromium project classified this as low severity internally, the CVSS score reflects the potential for complete system compromise once code execution is achieved.

  • CVE-2026-14090HIGH 8.1

    A vulnerability in Google Chrome's camera capture feature fails to properly validate untrusted input, allowing an attacker to craft a malicious HTML page that triggers an out-of-bounds memory read. An unsuspecting user who visits the compromised page could have sensitive data extracted from Chrome's memory. This affects Chrome on ChromeOS versions before 150.0.7871.47. While Google rates this internally as low severity, the CVSS score reflects the realistic risk: high confidence of exploitation and access to confidential information.

  • CVE-2026-14111HIGH 8.1

    A use-after-free vulnerability exists in Google Chrome's WebProtect component that could allow an attacker to run malicious code on a user's system. The vulnerability requires social engineering—specifically convincing a user to install a malicious browser extension—but once that hurdle is cleared, an attacker can execute arbitrary code with the privileges of the Chrome process. This affects Chrome versions prior to 150.0.7871.47 across Windows, macOS, and Linux systems.

  • CVE-2026-14122HIGH 8.1

    A flaw in Google Chrome's WebAppInstalls feature on Windows allows attackers to read and modify files on a victim's computer by tricking them into visiting a malicious website. The vulnerability requires user interaction—a victim must click or interact with a crafted webpage—but once triggered, it can expose sensitive data or alter files without additional restrictions. Google has patched this in Chrome 150.0.7871.47 and later.

  • CVE-2026-9964HIGH 8.1

    CVE-2026-9964 is a memory safety vulnerability in Chrome's Bluetooth implementation on macOS that can allow attackers to run malicious code on a victim's computer. The attack requires two user actions: the victim must first install a malicious Chrome extension, and then interact with Bluetooth functionality in a way that triggers the underlying flaw. Once those conditions are met, the attacker can execute arbitrary code with the same privileges as the Chrome process.

  • CVE-2025-48640HIGH 8.0

    CVE-2025-48640 is a privilege escalation vulnerability in Google Android where an attacker with local network proximity and low-level user privileges can bypass permission checks to approve third-party passkey pairings without the device owner's knowledge or action. This allows an attacker to gain elevated access to sensitive device functions and data.

  • CVE-2026-0059HIGH 8.0

    A heap buffer overflow vulnerability in Android's SDP (Session Description Protocol) discovery module allows an attacker on the same network segment to execute code with the privileges of the affected process. No user action is required, and the attacker needs only basic network access—the flaw can be triggered remotely through specially crafted SDP packets. This is a serious local/adjacent network attack vector that bypasses normal authentication and user interaction requirements.

  • CVE-2026-0095HIGH 8.0

    CVE-2026-0095 is a heap corruption flaw in Android's Bluetooth stack that allows a local attacker with limited privileges to escalate to higher system permissions. The vulnerability stems from an integer overflow in the l2c_fcr_clone_buf function, which can be manipulated to corrupt memory in the Bluetooth daemon process. Because this runs in a privileged context, successful exploitation grants elevated access without requiring additional tricks or user interaction.

  • CVE-2026-0097HIGH 8.0

    A logic error in Android's Bluetooth Low Energy (LE) pairing mechanism allows an attacker within wireless range to pair a device without requiring user approval or interaction. An attacker with local access to a Bluetooth-enabled Android device can escalate privileges by circumventing the normal pairing consent flow, potentially gaining full read, write, and execution access on the target device. This is particularly dangerous because it requires no user action to exploit.

  • CVE-2026-11241HIGH 8.0

    A vulnerability in Google Chrome's Cast feature allows an attacker on your local network to escalate their privileges on an affected machine by tricking a user into visiting a specially crafted web page. The attack requires the attacker to already be on your network segment and the user to interact with the malicious page, but once triggered, it grants elevated system access. Google rates this as a low-severity issue in Chromium, yet the CVSS 3.1 score reflects broader impact potential including confidentiality, integrity, and availability compromise.

  • CVE-2026-34693HIGH 8.0

    Adobe Experience Manager Forms JEE is vulnerable to a reflected cross-site scripting (XSS) flaw that allows attackers to inject malicious code into web pages. When a victim visits a specially crafted URL or interacts with a compromised page, the attacker can potentially hijack the user's session, escalate privileges, or take over their account. The vulnerability affects LTS SP1 and version 6.5.24.0 and earlier. Successful exploitation requires social engineering—tricking a user into clicking a malicious link or visiting a compromised site—but does not require the attacker to have direct system access.

  • CVE-2025-22424HIGH 7.8

    A vulnerability in Android allows a user with local access to view images that should be restricted to other users. The flaw stems from insufficient validation of user input across multiple code locations. While this requires someone already on the device and user interaction to exploit, it can lead to privilege escalation, meaning an attacker could gain elevated access to sensitive data and system resources.

  • CVE-2025-22426HIGH 7.8

    CVE-2025-22426 is a privilege escalation vulnerability in Android's ComputerEngine component that allows a local attacker with basic user-level access to bypass security boundaries and access resources (URIs) belonging to other users on the same device. The flaw stems from a logic error in multiple functions within ComputerEngine.java that fails to properly enforce cross-user access controls. An attacker needs only local access to the device and their own user account—no special permissions or user interaction required—making this a straightforward path to elevated privileges.

  • CVE-2025-26418HIGH 7.8

    A vulnerability in Android's device management system allows a local attacker with basic app permissions to bypass the user confirmation dialog that normally protects account additions on managed devices. This enables privilege escalation without requiring any special system access or user interaction. The flaw stems from a missing permission check in the CarDevicePolicyService component.

  • CVE-2025-32348HIGH 7.8

    CVE-2025-32348 is a privilege escalation vulnerability affecting Android that allows a local attacker to launch background activities without proper permission validation. An attacker with basic user-level access can exploit this flaw to gain elevated privileges on the device—no special capabilities or user interaction required. The vulnerability exists across multiple code paths where permission checks are missing, creating a consistent attack surface.

  • CVE-2025-48570HIGH 7.8

    A vulnerability in Android's PipTaskOrganizer component allows a malicious application with basic system privileges to launch activities from the background without user interaction. An attacker exploiting this flaw could escalate their privileges within the system, potentially gaining access to sensitive functionality or data. The vulnerability stems from a confused deputy issue—where a trusted system component is tricked into performing privileged actions on behalf of an unprivileged attacker.

  • CVE-2025-48617HIGH 7.8

    A permissions bypass vulnerability exists in Android's CarrierConfigLoader that allows an app with basic user-level access to escalate its privileges by circumventing UID validation checks. An attacker doesn't need special system permissions or user interaction to exploit this—just the ability to run code on the device with standard app-level rights. This means a malicious app could gain unauthorized access to sensitive functionality normally restricted to system components.

  • CVE-2025-48643HIGH 7.8

    CVE-2025-48643 is a high-severity local privilege escalation vulnerability affecting Google Android. An attacker with basic user-level access to a device can exploit improper input validation in the Android provisioning system to gain full system privileges without needing to execute additional code or interact with the user. Once exploited, the attacker gains complete control over the device, including access to all data and system functions.

  • CVE-2025-48649HIGH 7.8

    CVE-2025-48649 is a local privilege escalation vulnerability affecting Google Android in which an attacker with limited user privileges can reset user-selected permission settings, effectively bypassing the permissions model that Android uses to protect sensitive device capabilities. Because no additional privileges are needed and user interaction is not required, any application with basic local access can trigger this issue to gain unauthorized access to protected device functions—a significant departure from Android's intended permission architecture.

  • CVE-2025-48652HIGH 7.8

    A logic flaw in Android's application installation validation code allows a local attacker to bypass Mobile Device Management (MDM) security policies. An attacker with local access to the device can exploit this vulnerability to gain elevated privileges without requiring additional permissions or user interaction. MDM policies are a key security control for organizations managing corporate Android devices, making this bypass a significant concern for enterprise environments.

  • CVE-2026-0009HIGH 7.8

    A logic error in Android allows a local attacker to hijack touch input through tapjacking attacks, potentially gaining elevated privileges on the device. No special permissions or user interaction are required for exploitation, making this a direct path to privilege escalation for any app already running on the compromised system.

  • CVE-2026-0019HIGH 7.8

    CVE-2026-0019 is a privilege escalation vulnerability in Android's SettingsLib component that allows a local attacker with basic user-level access to disable critical system components and escalate their privileges to a higher level of control. The vulnerability stems from a logic error in the code and requires no user interaction to exploit, making it a straightforward attack vector for any app or process running on an affected device.

  • CVE-2026-0036HIGH 7.8

    CVE-2026-0036 is a tapjacking vulnerability in Android's StageCoordinator animation handler that allows a malicious app to escalate privileges without requiring user interaction or special permissions. An attacker with a local account on the device can overlay transparent windows to intercept touch events or manipulate the animation state, gaining unauthorized access to sensitive device functions and data. The vulnerability affects multiple Android versions and is rated HIGH severity due to its direct path to privilege escalation.

  • CVE-2026-0045HIGH 7.8

    A logic error in Android's Bluetooth RFCOMM connection handling allows a local attacker to bypass the bonding requirement for secure connections. An attacker with local access can escalate privileges without needing special permissions or user interaction, potentially gaining full control over sensitive device functions protected by Bluetooth pairing.

  • CVE-2026-0063HIGH 7.8

    A logic error in Android's phone service management allows a local attacker with basic user privileges to bypass carrier restrictions on a device. The vulnerability exists in code that controls which carriers are allowed to operate on the phone, and exploiting it requires only local access—no special permissions, user interaction, or additional steps. An attacker who gains a foothold on the device can remove or alter these carrier controls, potentially hijacking the device's cellular identity or enabling unauthorized network operations.

  • CVE-2026-0068HIGH 7.8

    A flaw in Android's PackageInstallerService allows an attacker to uninstall a Device Policy Controller (DPC) app—security software that enforces organizational policies on managed devices—without the Device Owner's knowledge or consent. The vulnerability stems from a synchronization gap between runtime state and persistent storage. An attacker would need to trick a user into installing a malicious app, after which the flaw could be exploited to remove critical management controls. This is particularly dangerous in corporate environments where DPC apps enforce compliance, security policies, and data protection.

  • CVE-2026-0071HIGH 7.8

    CVE-2026-0071 is a privilege escalation vulnerability in Android's SettingsLib component. A flaw in permission-checking logic allows a local attacker with basic user privileges to escalate to higher system permissions without needing to interact with the user or perform any additional actions. This is a logic error—not a memory corruption or injection flaw—making it a relatively straightforward vulnerability for attackers to exploit once they gain initial local access.

  • CVE-2026-0072HIGH 7.8

    A missing permission check in Android's input method manager allows a local attacker with minimal privileges to escalate their access and take full control of the affected device. No user action is required to exploit this flaw, making it a practical risk in multi-user or compromised environments.

  • CVE-2026-0076HIGH 7.8

    CVE-2026-0076 is a local privilege escalation vulnerability in Android's ResourceTypes.cpp component. An attacker with local access to a device can trigger an out-of-bounds memory read through a flawed bounds check in the validateNode function. Successful exploitation allows the attacker to escalate privileges without requiring additional permissions or user interaction, potentially gaining elevated system access.

  • CVE-2026-0077HIGH 7.8

    CVE-2026-0077 is a privilege escalation vulnerability in Android's ActivityRecord component that allows a local attacker with limited user privileges to launch background applications and gain elevated system access. The flaw stems from a logic error in the resumeConfigurationDispatch function that fails to properly validate or constrain application launch permissions. No special privileges or user interaction are required for exploitation, making this a straightforward attack vector for any app running on an affected device.

  • CVE-2026-0078HIGH 7.8

    A flaw in Android's device policy management system allows a local user to escalate their privileges by exploiting improper validation of proxy configuration settings. The vulnerability exists in how the system persists global proxy changes, creating a state mismatch that can be leveraged without requiring special permissions or user interaction. An attacker with basic local access can trigger the flaw to gain elevated system privileges.

  • CVE-2026-0081HIGH 7.8

    CVE-2026-0081 is a local privilege escalation flaw in Android's NFC (Near Field Communication) subsystem. An attacker with local access can forge NFC events by exploiting a missing permission check, allowing them to elevate their privileges without needing special system permissions or user interaction. This is a significant risk for multi-user or enterprise-managed Android devices where lateral movement or privilege abuse could unlock sensitive functionality.

  • CVE-2026-0082HIGH 7.8

    A flaw in Android's NFC (Near Field Communication) dispatcher allows a locally authenticated app to automatically gain special permissions it shouldn't have through an insecure default setting. An attacker with basic app-level access can exploit this without user interaction to escalate their privileges and potentially compromise confidentiality, integrity, and availability of system data. This is a local-only threat but poses meaningful risk in multi-app environments.

  • CVE-2026-0087HIGH 7.8

    A logic error in Android's domain verification service allows a local attacker to hijack app links associated with arbitrary applications. By exploiting this flaw, an attacker can redirect app links to malicious apps, potentially intercepting sensitive user actions or data. The vulnerability requires local access but no special permissions or user interaction, making it a meaningful escalation path on compromised or personally-owned devices.

  • CVE-2026-0088HIGH 7.8

    A flaw in Android's certificate installer component allows a malicious app with basic system privileges to bypass security dialogs that normally protect sensitive operations. By exploiting misleading UI presentation, an attacker can escalate their permissions without user knowledge or interaction. The vulnerability is particularly dangerous because it requires no special execution rights—a standard app can trigger it.

  • CVE-2026-0089HIGH 7.8

    CVE-2026-0089 is a vulnerability in Android's PackageInstallerService that allows a local attacker with basic user-level permissions to bypass security checks and install applications without proper verification. Because the vulnerability exists in multiple functions that lack proper permission validation, an attacker can escalate their privileges by sidestepping the normal app installation safeguards. No user interaction or special device access is required to exploit this flaw once an attacker has obtained standard user privileges on the device.

  • CVE-2026-0091HIGH 7.8

    A privilege escalation vulnerability exists in Android where an over-privileged shell user can execute arbitrary code within the launcher process. An attacker with local access can exploit this weakness to gain elevated privileges without needing special execution rights or user interaction. This is a local-only threat that targets the core launcher functionality central to Android's user interface and app management.

  • CVE-2026-0093HIGH 7.8

    CVE-2026-0093 is a local privilege escalation vulnerability affecting Google Android. The flaw stems from misleading user interface elements that obscure the true nature of certain operations, potentially tricking users into granting elevated permissions. An attacker with local access to the device can exploit this weakness to escalate privileges without needing special system permissions beforehand, and notably, without requiring any user interaction during the actual exploitation phase. The vulnerability allows an attacker to read, modify, or delete sensitive data and potentially take control of affected system functions.

  • CVE-2026-0094HIGH 7.8

    A flaw in Android's KeyChain component allows a local attacker with user-level privileges to manipulate the certificate approval interface in a way that tricks the system into granting access to certificates without explicit user consent. The vulnerability stems from misleading or incomplete UI messaging in the getApplicationLabel function, enabling privilege escalation entirely through local interaction. No special permissions or user action is required to exploit it once initiated.

  • CVE-2026-0096HIGH 7.8

    CVE-2026-0096 is a local privilege escalation vulnerability in Android's ForgetDeviceDialogFragment that allows an attacker with local access to manipulate or bypass a device-forget confirmation flow due to misleading UI elements. The vulnerability requires no user interaction to exploit and can result in unauthorized privilege escalation on the affected device.

  • CVE-2026-0098HIGH 7.8

    CVE-2026-0098 is a local privilege escalation vulnerability in Android's package-calling logic that allows a malicious app to bypass restrictions on which activities it can start. The flaw stems from a confused deputy problem—the system incorrectly trusts the calling context of an app requesting activity launches. An attacker with a local app installation can exploit this without special permissions or user interaction to gain elevated privileges, potentially accessing sensitive device functions or data reserved for system components.

  • CVE-2026-0099HIGH 7.8

    A vulnerability exists in Android's host emulation manager that allows a malicious app to launch activities (screen components) from the background without proper authorization. The flaw stems from a logic error in how the system validates binding requests. While an attacker needs to be a local user with some system access already, they can exploit this to gain elevated privileges on the device. The vulnerability requires user interaction to trigger—likely through social engineering or user action within a compromised app context.

  • CVE-2026-0100HIGH 7.8

    A heap buffer overflow vulnerability exists in Android's resource loading code (LoadedArsc.cpp) that allows a local attacker with standard user privileges to write data beyond the intended buffer boundaries. This memory corruption can be exploited to gain elevated system privileges without requiring special permissions or user interaction, making it a serious local privilege escalation vector.

  • CVE-2026-0133HIGH 7.8

    CVE-2026-0133 is a local privilege escalation vulnerability in Android's ARM SMMU v3 driver. An attacker with limited user-level access can bypass a missing permission check to sign malicious Android Runtime bootclass artifacts, gaining elevated system privileges without needing special rights or user interaction. This is a kernel-level flaw that allows an unprivileged local user to escalate their permissions substantially.

  • CVE-2026-0135HIGH 7.8

    CVE-2026-0135 is a buffer read vulnerability in Android's modem component that allows an attacker with local system access to execute arbitrary code without elevated privileges. The flaw stems from inadequate boundary checking when reading memory, potentially exposing sensitive data or enabling full system compromise. Exploitation requires no user action, making it a direct threat once an attacker gains initial foothold on a device.

  • CVE-2026-0137HIGH 7.8

    CVE-2026-0137 is a use-after-free memory vulnerability in Google Android's Edge TPU (Tensor Processing Unit) driver code. An attacker with local system access can exploit this flaw to escalate privileges and gain elevated system-level control. The vulnerability resides in the kernel-level driver for the Edge TPU hardware accelerator and does not require user interaction to trigger—a malicious process running with standard local privileges can execute the attack directly.

  • CVE-2026-0138HIGH 7.8

    CVE-2026-0138 is a memory corruption vulnerability in Android's light-weighted image stabilization (LWIS) subsystem that allows a local attacker with system-level privileges to write data beyond allocated buffer boundaries. An attacker who can trigger the vulnerable code path gains the ability to escalate privileges and execute arbitrary code with system permissions. No user interaction is required—the exploit can run silently once triggered.

  • CVE-2026-0143HIGH 7.8

    A use-after-free memory flaw exists in Google Android's Light Weight Image Sensor (LWIS) event handling code. An attacker with system-level privileges can trigger this defect to corrupt memory and escalate their access, potentially running arbitrary code with elevated system privileges. No user interaction is required—the vulnerability can be exploited automatically once the attacker has obtained initial system access.