VENDOR

Google vulnerabilities: CVEs, exploitation and patches (page 2)

Every Google CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-78905
    Chrome ANGLE type confusion allows remote code execution from a web page Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  2. CVE-2026-78938
    Chrome type confusion in V8 remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  3. CVE-2026-79266
    Chrome DevTools use-after-free allows extension to execute code Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  4. CVE-2026-28618 HIGH 8.8
  5. CVE-2026-28609 HIGH 8.8
  6. CVE-2026-58704
    Pixel cellular modem permission bypass privilege escalation Google Pixel ·
    • CISA KEV
    • EXPLOITED
    HIGH 8.8
  7. CVE-2026-14382
    Chrome ANGLE sandbox escape via crafted HTML Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.6
  8. CVE-2026-76036
    Chrome Dawn buffer overflow remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.6
  9. CVE-2026-78904
    Chrome ANGLE type confusion remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.6
  10. CVE-2026-87492
    Chrome DevTools incorrect authorization allows remote code execution Google Chrome ·
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.6
  11. CVE-2026-85046
    Chromium V8 type confusion remote code execution Google Chromium V8 ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
  12. CVE-2026-87491
    Chromium V8 out-of-bounds write remote code execution Google Chromium V8 ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    HIGH 8.8
12 CVEs · page 2 of 2