PatchSiren

Google CVE debriefs · Page 49

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Google CVE published 2026-03-02

CVE-2026-0008

CVE-2026-0008 is a high-severity privilege escalation vulnerability in FaceEnroll.kt, which could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. This vulnerability affects Android systems and devices using FaceEnroll.kt. Defenders should assess exposure and prioritize patching. The CVE record and NVD entry provide deta [truncated]

Known exploited Google CVE published 2026-02-17

CVE-2026-2441

CVE-2026-2441 is a Google Chromium CSS use-after-free vulnerability that CISA has placed in its Known Exploited Vulnerabilities catalog. Because it is KEV-listed, defenders should treat it as a high-priority browser risk and move quickly on vendor guidance, patching, and any interim mitigations.

HIGH Google CVE published 2026-02-11

CVE-2026-1669

CVE-2026-1669 is a high-severity vulnerability in Keras, a popular deep learning library. The vulnerability allows remote attackers to read local files and disclose sensitive information via a crafted .keras model file utilizing HDF5 external dataset references. This vulnerability affects Keras versions 3.0.0 through 3.13.1 on all supported platforms. The CVSS score for this vulnerability is 7.1, indicati [truncated]

HIGH Google CVE published 2026-01-23

CVE-2026-0994

CVE-2026-0994 is a denial-of-service (DoS) vulnerability in Google Protobuf, specifically in the google.protobuf.json_format.ParseDict() function in Python. The vulnerability allows an attacker to bypass the max_recursion_depth limit when parsing nested google.protobuf.Any messages, leading to a RecursionError. This vulnerability was published on January 23, 2026, and modified on June 30, 2026. The CVSS s [truncated]

HIGH Google CVE published 2026-01-22

CVE-2026-1260

CVE-2026-1260 is a HIGH severity vulnerability in Sentencepiece, a library developed by Google. The vulnerability allows for invalid memory access when using a vulnerable model file, which is not created in the normal training procedure. This issue was published on January 22, 2026, and modified on June 30, 2026. The CVSS score for this vulnerability is 8.5. The vulnerability is classified under CWE-119. [truncated]

HIGH Google CVE published 2026-01-15

CVE-2026-0897

CVE-2026-0897 is a HIGH severity vulnerability in Google Keras 3.0.0 through 3.13.0 on all platforms. The vulnerability allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape. This issue is caused by the Allocation of Res [truncated]

Known exploited Google CVE published 2025-12-12

CVE-2025-14174

CVE-2025-14174 is a Google Chromium out-of-bounds memory access vulnerability that CISA lists in the Known Exploited Vulnerabilities (KEV) catalog. That KEV status makes this a high-priority remediation item even though the supplied public record does not include a CVSS score or deeper technical detail. The safest defensive posture is to confirm you are running a fixed Chromium build and to complete remed [truncated]

Known exploited Google CVE published 2025-11-19

CVE-2025-13223

CVE-2025-13223 is a Google Chromium V8 type confusion vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-11-19. Because it is in KEV, defenders should treat it as urgent and follow vendor remediation guidance promptly, with the CISA due date set for 2025-12-10.

Known exploited Google CVE published 2025-09-23

CVE-2025-10585

CVE-2025-10585 was added to CISA’s Known Exploited Vulnerabilities catalog on 2025-09-23, which makes it a high-priority issue for defenders even though the supplied corpus does not include a CVSS score. The public evidence identifies it as a Google Chromium V8 type confusion vulnerability; organizations should treat affected Chromium-based deployments as urgent remediation candidates and follow vendor gu [truncated]

Known exploited Google CVE published 2025-07-22

CVE-2025-6558

CVE-2025-6558 affects Google Chromium and is described as an improper input validation issue in the ANGLE and GPU components. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-22, which means it is considered actively exploited and should be prioritized for remediation.

Known exploited Google CVE published 2025-07-02

CVE-2025-6554

CVE-2025-6554 is a Google Chromium V8 type confusion vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-07-02. Because it is listed as known exploited, organizations should treat it as a high-priority remediation item even though the supplied public source set does not include a CVSS score or detailed technical impact. The key operational action is to follow vendor guidan [truncated]

Known exploited Google CVE published 2025-06-05

CVE-2025-5419

CVE-2025-5419 is a Google Chromium V8 out-of-bounds read and write vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-06-05. Because it is on the KEV list, defenders should treat it as an actively exploited issue and prioritize vendor mitigation and update actions over routine patch cycles.

Known exploited Google CVE published 2025-03-27

CVE-2025-2783

CVE-2025-2783 is a Google Chromium Mojo sandbox escape vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-03-27. Because CISA classifies it as known exploited, defenders should treat it as a high-priority browser and Chromium-component issue and follow vendor mitigation guidance promptly. CISA’s due date for remediation is 2025-04-17.

Known exploited Google CVE published 2024-08-28

CVE-2024-7965

CVE-2024-7965 is a Google Chromium V8 inappropriate implementation vulnerability that CISA added to its Known Exploited Vulnerabilities (KEV) catalog on 2024-08-28. The supplied record does not include a CVSS score or a fuller public impact description, but KEV inclusion means defenders should treat it as actively exploited risk and follow vendor mitigation guidance promptly. CISA’s catalog entry sets a r [truncated]

Known exploited Google CVE published 2024-08-26

CVE-2024-7971

CVE-2024-7971 is a Google Chromium V8 type confusion vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-08-26. Because it is listed as known exploited, defenders should treat it as a priority remediation item and follow vendor guidance from the linked Google Chrome release information and CISA KEV entry.

Known exploited Google CVE published 2024-05-28

CVE-2024-5274

CVE-2024-5274 is a Google Chromium V8 type confusion vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-05-28. Because CISA lists it as known exploited and set a mitigation deadline of 2024-06-18, affected organizations should prioritize vendor guidance and remediation immediately.

Known exploited Google CVE published 2024-05-20

CVE-2024-4947

CVE-2024-4947 is a Google Chromium V8 type confusion vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-05-20. The available source corpus does not provide deeper technical mechanics, but the KEV entry means defenders should treat it as a confirmed-exploitation issue and follow Google’s mitigation guidance promptly.

Known exploited Google CVE published 2024-05-16

CVE-2024-4761

CVE-2024-4761 is a Google Chromium V8 out-of-bounds memory write vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-05-16. KEV inclusion means CISA has identified active exploitation risk, so defenders should treat this as an urgent browser and embedded V8 remediation item rather than a routine advisory. The official guidance is to apply vendor mitigations or discontinue [truncated]

Known exploited Google CVE published 2024-05-13

CVE-2024-4671

CVE-2024-4671 is a Google Chromium vulnerability affecting the Visuals component and classified as a use-after-free issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-05-13, which means defenders should treat it as actively exploited and prioritize remediation.

Known exploited Google CVE published 2024-02-06

CVE-2023-4762

CVE-2023-4762 is a Google Chromium V8 type confusion vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-02-06. Because it is listed in KEV, defenders should treat it as a high-priority issue and follow vendor guidance promptly. The supplied corpus does not include deeper technical detail or CVSS scoring, so remediation urgency here is driven primarily by known exploitatio [truncated]

Known exploited Google CVE published 2024-01-17

CVE-2024-0519

CVE-2024-0519 is a Google Chromium V8 out-of-bounds memory access vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-01-17. Because it is in the KEV catalog, defenders should treat it as a priority issue and follow vendor guidance or mitigate exposure where the affected component is in use.

Known exploited Google CVE published 2024-01-02

CVE-2023-7024

CVE-2023-7024 is a Google Chromium WebRTC heap buffer overflow that CISA placed in its Known Exploited Vulnerabilities catalog. In the supplied corpus, that makes it a high-priority defensive item: CISA’s guidance is to apply vendor mitigations or discontinue use if mitigations are unavailable. Because WebRTC is a shared component used across different products, defenders should check the specific vendor [truncated]

Known exploited Google CVE published 2023-11-30

CVE-2023-6345

CVE-2023-6345 is a Google Chromium Skia integer overflow vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-11-30. Because it is on the KEV list, defenders should treat it as a live risk signal and validate patch status or mitigations promptly. CISA’s entry directs organizations to apply vendor mitigations or discontinue use of the product if mitigations are not available [truncated]

Known exploited Google CVE published 2023-10-02

CVE-2023-5217

CVE-2023-5217 is a heap buffer overflow in Google Chromium libvpx. CISA lists it in the Known Exploited Vulnerabilities catalog, which makes it an urgent remediation item rather than a routine patching task. Defenders should prioritize vendor-provided mitigations or updates for affected Chromium/libvpx deployments and, if those are not available, discontinue use of the affected product path.

Known exploited Google CVE published 2023-09-13

CVE-2023-4863

CVE-2023-4863 is a Google Chromium WebP heap-based buffer overflow vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-09-13. Because it is on the KEV list, defenders should treat remediation as urgent and follow vendor guidance for affected Chromium/WebP deployments.

Known exploited Google CVE published 2023-06-07

CVE-2023-3079

CVE-2023-3079 affects Google Chromium V8 and was added to CISA’s Known Exploited Vulnerabilities catalog on 2023-06-07. Because CISA flags it as known exploited, organizations should treat remediation as urgent and apply vendor updates without delay.

Known exploited Google CVE published 2023-04-21

CVE-2023-2136

CVE-2023-2136 is a Google Chromium Skia integer overflow vulnerability associated with Google Chrome/Chromium. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-21, which means it was already considered known to be exploited in the wild. The defensive takeaway is straightforward: prioritize the vendor-recommended update and verify browser fleet patching quickly.

Known exploited Google CVE published 2023-04-17

CVE-2023-2033

CVE-2023-2033 is a Google Chromium V8 type confusion vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2023-04-17. Because it is in KEV, defenders should treat it as urgent and follow vendor update guidance without delay.

Known exploited Google CVE published 2023-03-30

CVE-2022-3038

CVE-2022-3038 is a Google Chromium Network Service use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-03-30. Because it is a KEV-listed issue, defenders should treat patching as urgent and follow vendor guidance to update affected Chromium-based browsers and components as soon as possible.

Known exploited Google CVE published 2022-12-05

CVE-2022-4262

CVE-2022-4262 is a Google Chromium V8 type confusion vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-12-05. Because CISA marked it as known exploited and set a remediation due date of 2022-12-26, defenders should treat patching as urgent and verify that vendor updates have been applied across all affected deployments.