Exploited CVEs / By vendor / Google

Google vulnerabilities actively exploited

72 Google CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2026-11645 (Chromium V8, added 2026-06-09). New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

72 exploited CVEs
Senserva AI Opinion and rich prompt for Google exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

Chromium V8: 39 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-11645Chromium V82026-06-09CVSS 8.8, EPSS 2%
CVE-2026-3910Chromium V82026-03-13CVSS 8.8, EPSS 2%
CVE-2025-13223Chromium V82025-11-19CVSS 8.8, EPSS 5%
CVE-2025-10585Chromium V82025-09-23CVSS 9.8, EPSS 5%
CVE-2025-6554Chromium V82025-07-02CVSS 8.1, EPSS 13%
CVE-2025-5419Chromium V82025-06-05CVSS 8.8, EPSS 6%
CVE-2024-7965Chromium V82024-08-28CVSS 8.8, EPSS 18%
CVE-2024-7971Chromium V82024-08-26CVSS 9.6, EPSS 21%
CVE-2024-5274Chromium V82024-05-28CVSS 9.6, EPSS 10%
CVE-2024-4947Chromium V82024-05-20CVSS 9.6, EPSS 15%
CVE-2024-4761Chromium V82024-05-16CVSS 8.8, EPSS 11%
CVE-2023-4762Chromium V82024-02-06CVSS 8.8, EPSS 38%
CVE-2024-0519Chromium V82024-01-17CVSS 8.8, EPSS 4%
CVE-2023-3079Chromium V82023-06-07CVSS 8.8, EPSS 32%
CVE-2023-2033Chromium V82023-04-17CVSS 8.8, EPSS 41%
CVE-2022-4262Chromium V82022-12-05CVSS 8.8, EPSS 15%
CVE-2022-3723Chromium V82022-10-28CVSS 8.8, EPSS 8%
CVE-2016-1646Chromium V82022-06-08CVSS 8.8, EPSS 48%
CVE-2016-5198Chromium V82022-06-08CVSS 8.8, EPSS 35%
CVE-2017-5030Chromium V82022-06-08CVSS 8.8, EPSS 42%
CVE-2017-5070Chromium V82022-06-08CVSS 8.8, EPSS 31%
CVE-2018-17463Chromium V82022-06-08CVSS 8.8, EPSS 85%
CVE-2018-17480Chromium V82022-06-08CVSS 8.8, EPSS 36%
CVE-2018-6065Chromium V82022-06-08CVSS 8.8, EPSS 60%
CVE-2019-5825Chromium V82022-06-08CVSS 6.5, EPSS 56%
CVE-2022-1364Chromium V82022-04-15CVSS 8.8, EPSS 14%
CVE-2022-1096Chromium V82022-03-28CVSS 8.8, EPSS 24%
CVE-2021-4102Chromium V82021-12-15CVSS 8.8, EPSS 8%
CVE-2020-16009Chromium V82021-11-03CVSS 8.8, EPSS 49%
CVE-2020-16013Chromium V82021-11-03CVSS 8.8, EPSS 3%
CVE-2020-6418Chromium V82021-11-03CVSS 8.8, EPSS 79%
CVE-2021-21148Chromium V82021-11-03CVSS 8.8, EPSS 20%
CVE-2021-21220Chromium V82021-11-03CVSS 8.8, EPSS 69%
CVE-2021-21224Chromium V82021-11-03CVSS 8.8, EPSS 56%
CVE-2021-30551Chromium V82021-11-03CVSS 8.8, EPSS 65%
CVE-2021-30563Chromium V82021-11-03CVSS 8.8, EPSS 9%
CVE-2021-30632Chromium V82021-11-03CVSS 8.8, EPSS 65%
CVE-2021-37975Chromium V82021-11-03CVSS 8.8, EPSS 35%
CVE-2021-38003Chromium V82021-11-03CVSS 8.8, EPSS 39%

Chromium: 6 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-2441Chromium2026-02-17CVSS 8.8, EPSS 22%
CVE-2025-14174Chromium2025-12-12CVSS 8.8, EPSS 23%
CVE-2025-6558Chromium2025-07-22CVSS 8.8, EPSS 9%
CVE-2024-4671Chromium2024-05-13CVSS 9.6, EPSS 8%
CVE-2021-21166Chromium2021-11-03CVSS 8.8, EPSS 24%
CVE-2021-37976Chromium2021-11-03CVSS 6.5, EPSS 20%

Other Google products

CVEProductAdded to KEVSignals
CVE-2026-5281Dawn2026-04-01CVSS 8.8, EPSS 5%
CVE-2026-3909Skia2026-03-13CVSS 8.8, EPSS 2%
CVE-2025-2783Chromium Mojo2025-03-27CVSS 8.3, EPSS 8%
CVE-2023-7024Chromium WebRTC2024-01-02CVSS 8.8, EPSS 7%
CVE-2023-6345Chromium Skia2023-11-30CVSS 9.6, EPSS 19%
CVE-2023-5217Chromium libvpx2023-10-02CVSS 8.8, EPSS 49%
CVE-2023-4863Chromium WebP2023-09-13CVSS 8.8, EPSS 100%
CVE-2023-2136Chromium Skia2023-04-21CVSS 9.6, EPSS 6%
CVE-2022-3038Chromium Network Service2023-03-30CVSS 8.8, EPSS 25%
CVE-2022-4135Chromium GPU2022-11-28CVSS 9.6, EPSS 32%
CVE-2022-3075Chromium Mojo2022-09-08CVSS 9.6, EPSS 6%
CVE-2022-2856Chromium Intents2022-08-18CVSS 6.5, EPSS 5%
CVE-2021-30533Chromium PopupBlocker2022-06-27CVSS 6.5, EPSS 17%
CVE-2019-13720Chrome WebAudio2022-05-23CVSS 8.8, EPSS 49%
CVE-2019-5786Chrome Blink2022-05-23CVSS 6.5, EPSS 62%
CVE-2021-39793Pixel2022-04-11CVSS 7.8, EPSS 1%
CVE-2022-0609Chromium Animation2022-02-15CVSS 8.8, EPSS 21%
CVE-2020-6572Chrome Media2022-01-10CVSS 8.8, EPSS 11%
CVE-2020-15999Chrome FreeType2021-11-03CVSS 9.6, EPSS 44%
CVE-2020-16010Chrome for Android UI2021-11-03CVSS 9.6, EPSS 6%
CVE-2020-16017Chrome2021-11-03CVSS 9.6, EPSS 3%
CVE-2021-21193Chromium Blink2021-11-03CVSS 8.8, EPSS 10%
CVE-2021-21206Chromium Blink2021-11-03CVSS 8.8, EPSS 9%
CVE-2021-30554Chromium WebGL2021-11-03CVSS 8.8, EPSS 7%
CVE-2021-30633Chromium Indexed DB API2021-11-03CVSS 9.6, EPSS 33%
CVE-2021-37973Chromium Portals2021-11-03CVSS 9.6, EPSS 12%
CVE-2021-38000Chromium Intents2021-11-03CVSS 6.1, EPSS 5%

Common questions about exploited Google CVEs

Which Google vulnerabilities are actively exploited?

As of August 2026, 72 Google CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are Chromium V8 (39), Chromium (6).

What is the newest exploited Google CVE?

CVE-2026-11645, affecting Chromium V8, added to the CISA KEV catalog on 2026-06-09. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these Google CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited Google CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest Google KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.