google security advisories
60 threat alerts tracking vulnerabilities and security advisories that affect google products.
Vulnios monitors google CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent google security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2020-16045 — google — chrome, android
Use after Free in Payments in Google Chrome on Android prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HT
criticalCVE-2020-16045Critical Vulnerability: CVE-2021-0316 — google — android
In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution
criticalCVE-2021-0316Critical Vulnerability: CVE-2020-0471 — google — android
In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper input validation. This could lead to remote escalat
criticalCVE-2020-0471Critical Vulnerability: CVE-2021-21115 — google, fedoraproject — chrome, fedora
User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML p
criticalCVE-2021-21115Critical Vulnerability: CVE-2020-16018 — google — chrome
Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
criticalCVE-2020-16018Critical Vulnerability: CVE-2020-16014 — google — chrome
Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
criticalCVE-2020-16014Critical Vulnerability: CVE-2020-16024 — google — chrome, chrome_os
Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
criticalCVE-2020-16024Critical Vulnerability: CVE-2020-16016 — google — chrome
Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HT
criticalCVE-2020-16016Critical Vulnerability: CVE-2021-21111 — google, fedoraproject — chrome, fedora
Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a
criticalCVE-2021-21111Critical Vulnerability: CVE-2021-21107 — google, linux — chrome, linux_kernel
Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafte
criticalCVE-2021-21107Critical Vulnerability: CVE-2021-21108 — google, fedoraproject — chrome, fedora
Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
criticalCVE-2021-21108Critical Vulnerability: CVE-2021-21110 — google, fedoraproject — chrome, fedora
Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
criticalCVE-2021-21110Critical Vulnerability: CVE-2021-21109 — google, fedoraproject — chrome, fedora
Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
criticalCVE-2021-21109Critical Vulnerability: CVE-2020-16025 — google — chrome
Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML p
criticalCVE-2020-16025Critical Vulnerability: CVE-2021-21106 — google, fedoraproject — chrome, fedora
Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
criticalCVE-2021-21106Critical Vulnerability: CVE-2019-25004 — google — flatbuffers
An issue was discovered in the flatbuffers crate before 0.6.1 for Rust. Arbitrary bytes can be reinterpreted as a bool, defeating soundness.
criticalCVE-2019-25004Critical Vulnerability: CVE-2020-35550 — google — android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via StatusBar. The Samsung ID is SVE-2020-1788
criticalCVE-2020-35550Critical Vulnerability: CVE-2020-35551 — google — android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. They allow attackers to conduct RPMB state-change attacks because an unauthorized RPMB wr
criticalCVE-2020-35551Critical Vulnerability: CVE-2020-27068 — google — android
Product: AndroidVersions: Android kernelAndroid ID: A-127973231References: Upstream kernel
criticalCVE-2020-27068Critical Vulnerability: CVE-2020-0455 — google — android
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170372514
criticalCVE-2020-0455Critical Vulnerability: CVE-2020-0456 — google — android
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170378843
criticalCVE-2020-0456Critical Vulnerability: CVE-2020-0457 — google — android
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170367562
criticalCVE-2020-0457Critical Vulnerability: CVE-2020-0452 — google, fedoraproject — android, fedora
In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process
criticalCVE-2020-0452Critical Vulnerability: CVE-2020-0447 — google — android
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168251617
criticalCVE-2020-0447Critical Vulnerability: CVE-2020-0445 — google — android
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168264527
criticalCVE-2020-0445Critical Vulnerability: CVE-2020-0446 — google — android
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168264528
criticalCVE-2020-0446Critical Vulnerability: CVE-2020-28340 — google — android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via Secure Folder. The Samsung ID is SVE-2020-
criticalCVE-2020-28340Critical Vulnerability: CVE-2020-16011 — google, microsoft — chrome, windows
Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted H
criticalCVE-2020-16011Critical Vulnerability: CVE-2020-15993 — google — chrome, android
Use after free in printing in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
criticalCVE-2020-15993Critical Vulnerability: CVE-2020-0376 — google — android
There is a possible out of bounds read due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-163003156
criticalCVE-2020-0376Critical Vulnerability: CVE-2020-0283 — google — android
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-163008257
criticalCVE-2020-0283Critical Vulnerability: CVE-2020-0367 — google — android
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-162980455
criticalCVE-2020-0367Critical Vulnerability: CVE-2020-0339 — google — android
There is a possible out of bounds read due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-162980705
criticalCVE-2020-0339Critical Vulnerability: CVE-2020-0371 — google — android
There is a possible out of bounds read due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-163008256
criticalCVE-2020-0371Critical Vulnerability: CVE-2020-26607 — google — android
An issue was discovered in TimaService on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. PendingIntent with an empty intent is mishandled, allowing an attacker to perform a privileg
criticalCVE-2020-26607Critical Vulnerability: CVE-2020-15206 — google, opensuse — tensorflow, leap
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of required keys results in segfaults and data corrupt
criticalCVE-2020-15206Critical Vulnerability: CVE-2020-15205 — google, opensuse — tensorflow, leap
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap ove
criticalCVE-2020-15205Critical Vulnerability: CVE-2020-15202 — google, opensuse — tensorflow, leap
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking two `int64` (i.e., `long long`) arguments. However,
criticalCVE-2020-15202Critical Vulnerability: CVE-2020-6573 — google, opensuse — chrome, backports_sle
Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML
criticalCVE-2020-6573Critical Vulnerability: CVE-2020-15961 — google, opensuse — chrome, backports_sle
Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape v
criticalCVE-2020-15961Critical Vulnerability: CVE-2020-15963 — google, opensuse — chrome, backports_sle
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape
criticalCVE-2020-15963Critical Vulnerability: CVE-2020-0278 — google — android
There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-160812574
criticalCVE-2020-0278Critical Vulnerability: CVE-2020-0380 — google — android
In allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. Use
criticalCVE-2020-0380Critical Vulnerability: CVE-2020-0354 — google — android
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not ne
criticalCVE-2020-0354Critical Vulnerability: CVE-2020-0123 — google — android
There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-149871374
criticalCVE-2020-0123Critical Vulnerability: CVE-2020-0333 — google — android
In UrlQuerySanitizer, there is a possible improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploit
criticalCVE-2020-0333Critical Vulnerability: CVE-2020-0342 — google — android
There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-160812576
criticalCVE-2020-0342Critical Vulnerability: CVE-2020-0229 — google — android
There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-156333725
criticalCVE-2020-0229Critical Vulnerability: CVE-2020-25279 — google — android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The baseband component has a buffer overflow via an abnormal SETUP message, leading to ex
criticalCVE-2020-25279Critical Vulnerability: CVE-2020-25278 — google — android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The Quram image codec library allows attackers to overwrite memory and execute arbitrary code via crafted J
criticalCVE-2020-25278Critical Vulnerability: CVE-2020-25283 — google — android
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers to bypass intended access restrictions on a certain mode. The LG ID is LVE-SMP-
criticalCVE-2020-25283Critical Vulnerability: CVE-2020-25282 — google — android
An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on
criticalCVE-2020-25282Critical Vulnerability: CVE-2020-25053 — google, samsung — android, exynos_9830
An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code execution. The Samsung ID is SVE-2020-17435 (August 2020).
criticalCVE-2020-25053Critical Vulnerability: CVE-2020-25062 — google — android
An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of intended privilege restrictions. The LG ID is LVE-SMP-200017 (July 2020).
criticalCVE-2020-25062Critical Vulnerability: CVE-2020-25049 — google — android
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. StatusBarService has insufficient DEX access control. The Samsung ID is SVE-2020-17797 (August 2020).
criticalCVE-2020-25049Critical Vulnerability: CVE-2020-25055 — google — android
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unprivileged SecureFolder process) to bypass admin res
criticalCVE-2020-25055Critical Vulnerability: CVE-2020-25061 — google — android
An issue was discovered on LG mobile devices with Android OS 9 and 10 software on the VZW network. lge_property allows property overwrites. The LG ID is LVE-SMP-200016 (July 2020).
criticalCVE-2020-25061Critical Vulnerability: CVE-2020-25052 — google, samsung — android, exynos_9830
An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. H-Arx allows attackers to execute arbitrary code or cause a denial of service (memory corruption) because
criticalCVE-2020-25052Critical Vulnerability: CVE-2020-25058 — google — android
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management service does not properly restrict configuration changes. The LG ID is LVE-SMP-200012
criticalCVE-2020-25058Critical Vulnerability: CVE-2020-25057 — google — android
An issue was discovered on LG mobile devices with Android OS 10 software. MDMService does not properly restrict APK installations. The LG ID is LVE-SMP-200011 (July 2020).
criticalCVE-2020-25057
Showing the 60 most recent. Older alerts are archived but still reachable via search and the main feed.
Track google exposure across your environment
Vulnios automatically cross-references your asset inventory against new google CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan