Skip to content
COOEY

FAIL › dossier

Google

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 20%

Google Chrome is currently under active exploitation due to a cluster of critical sandbox escape and RCE vulnerabilities in core components like V8 and Skia, with multiple patches released in July 2026 to address these high-risk flaws.

PROFILE
CategoryTechnology VendorWhat they doGoogle is a multinational technology company that develops and provides various internet-based services and products, including the Chrome web browser. Websitehttps://www.google.com ↗
SECURITY POSTURE

Google demonstrates a reactive security posture with a high volume of critical and high-severity vulnerabilities in Chrome, particularly involving sandbox escape and use-after-free flaws in core components like V8, Skia, and ANGLE.

Notable failures
  • CVE-2026-14104: Critical RCE in WebAppInstalls
  • CVE-2026-13782: Critical Sandbox Escape in Browser
  • CVE-2026-13781: Critical Sandbox Escape in Skia
  • CVE-2026-13776: Critical Sandbox Escape in Dawn
  • CVE-2026-13775: Critical Sandbox Escape in GPU
  • CVE-2026-11720: Critical Path Traversal in googleapis/mcp-toolbox
Patterns: Repeated unpatched edge-device RCEs; Sandbox escape via renderer process compromise; Use-after-free vulnerabilities in core rendering components
FAILURE HISTORY · 60
DATEEVENTSEVSUMMARY
2026-03-13 CVE-2026-3910 high Google Chromium V8 allows remote code execution via crafted HTML pages, enabling attackers to bypass sandbox protections.
2022-05-23 CVE-2019-13720 high A use-after-free vulnerability in Google Chrome's WebAudio component allowed remote attackers to exploit heap corruption via a crafted HTML page.
2021-11-03 CVE-2021-21220 high A remote attacker could exploit heap corruption via a crafted HTML page in Google Chromium V8 to execute arbitrary code.
2022-05-23 CVE-2019-5786 high A use-after-free vulnerability in Chrome Blink allowed out-of-bounds memory access via a crafted HTML page and was actively exploited in the wild.
2022-04-11 CVE-2021-39793 high A local privilege escalation vulnerability in Google Pixel devices was actively exploited in the wild, highlighting the risks of unpatched hardware in defense supply chains.
2022-02-15 CVE-2022-0609 high A use-after-free vulnerability in Google Chromium's animation code allowed remote attackers to exploit heap corruption via crafted HTML pages.
2022-01-10 CVE-2020-6572 high A use-after-free vulnerability in Google Chrome's media component allowed remote code execution via a crafted HTML page and was actively exploited in the wild.
2021-11-03 CVE-2021-21166 high A race condition in Google Chromium allows remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-21193 high A use-after-free vulnerability in Google Chromium Blink allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-21224 high A type confusion vulnerability in Google Chromium V8 allowed remote code execution inside a browser sandbox via a crafted HTML page.
2021-11-03 CVE-2021-21206 high A use-after-free vulnerability in Google Chromium Blink allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-30551 high A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-37973 high A use-after-free vulnerability in Google Chromium Portals allowed sandbox escapes via crafted HTML pages after the renderer process was compromised.
2021-11-03 CVE-2021-21148 high A heap buffer overflow in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-30632 high An out-of-bounds write vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2020-15999 high A heap buffer overflow in Google Chrome's FreeType font rendering library was actively exploited in the wild as part of an exploit chain.
2022-04-15 CVE-2022-1364 high A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2022-03-28 CVE-2022-1096 high A type confusion vulnerability in Google's Chromium V8 engine allowed remote attackers to exploit heap corruption via crafted HTML pages.
2021-12-15 CVE-2021-4102 high A use-after-free vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-37975 high A use-after-free vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2020-6418 high A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-30563 high A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-30554 high A use-after-free vulnerability in Google Chromium WebGL allowed remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2020-16009 high A type confusion vulnerability in Google's Chromium V8 engine allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2026-02-17 CVE-2026-2441 high Chrome rce due to CSS use-after-free
2025-12-12 CVE-2025-14174 high Google Chromium out-of-bounds memory access flaw exploited
2025-11-19 CVE-2025-13223 high Google Chromium V8 heap corruption
2025-09-23 CVE-2025-10585 high Google Chromium V8 had an unpatched type confusion vulnerability actively exploited in the wild
2025-07-22 CVE-2025-6558 high Google Chromium ANGLE and GPU input validation flaw exploited remotely
2025-07-02 CVE-2025-6554 high Google Chromium V8 had a type confusion vulnerability exploited in the wild
2025-06-05 CVE-2025-5419 high Google Chromium V8 OOB Read/Write Vuln exploited
2025-03-27 CVE-2025-2783 high A logic error in Google Chromium's Mojo sandbox allows for potential escape, impacting browsers like Chrome and Edge and actively being exploited in the wild.
2023-11-30 CVE-2023-6345 high A Google Skia integer overflow vulnerability allowed sandbox escape via a malicious file, actively exploited in the wild and impacting Chrome, ChromeOS, Android, and Flutter products.
2023-10-02 CVE-2023-5217 high Google Chromium libvpx heap buffer overflow allows remote code execution.
2023-06-07 CVE-2023-3079 high Google Chromium V8 Type Confusion Vulnerability allows remote code execution.
2023-04-21 CVE-2023-2136 high Google Chrome Skia Integer Overflow Vulnerability
2023-04-17 CVE-2023-2033 high Google Chromium V8 Type Confusion Vulnerability allows remote code execution.
2023-03-30 CVE-2022-3038 high Google Chromium Network Service Use-After-Free Vulnerability exploited remotely
2022-12-05 CVE-2022-4262 high Google Chromium V8 Engine had a type confusion vulnerability actively exploited in the wild
2022-11-28 CVE-2022-4135 high Google Chromium GPU heap buffer overflow allowed remote attacker to escape sandbox
2022-10-28 CVE-2022-3723 high Google Chromium V8 Engine had a type confusion vulnerability actively exploited in the wild
2022-09-08 CVE-2022-3075 high Google Chromium Mojo allows remote attackers to escape the sandbox via a crafted HTML page.
2022-08-18 CVE-2022-2856 high Google Chromium Intents CVE-2022-2856 allows remote code execution via malicious HTML pages
2022-06-27 CVE-2021-30533 high A Chromium PopupBlocker vulnerability allowed attackers to bypass navigation restrictions via crafted iframes, impacting multiple browsers including Chrome and Edge, and actively exploited in the wild.
2022-06-08 CVE-2018-17463 high A Chromium V8 vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers and potentially DIB organizations using them for web access or internal tools.
2022-06-08 CVE-2017-5030 high A memory corruption vulnerability in Google's Chromium V8 engine allowed remote code execution via crafted HTML pages, impacting multiple browsers including Chrome and Edge, and actively exploited in the wild.
2022-06-08 CVE-2018-17480 high A Chromium V8 out-of-bounds write vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers including Chrome and Edge, and is currently being exploited in the wild.
2022-06-08 CVE-2019-5825 high A heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via a crafted HTML page.
2022-06-08 CVE-2016-1646 high A Chromium V8 out-of-bounds read vulnerability was actively exploited, impacting browsers like Chrome and Edge, potentially causing denial of service or other impacts.
2022-06-08 CVE-2018-6065 high A heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via crafted HTML pages.
2021-11-03 CVE-2021-37976 high A remote attacker could extract sensitive data from Chromium browser processes via a crafted HTML page due to an unpatched memory disclosure flaw.
2026-06-09 CVE-2026-11645 high Google Chromium V8 allows remote code execution via crafted HTML pages, enabling sandbox escape and arbitrary code execution.
2024-05-20 CVE-2024-4947 high Google Chromium V8 allows remote code execution via a type confusion vulnerability in a crafted HTML page.
2024-01-02 CVE-2023-7024 high Google Chromium WebRTC suffered a heap buffer overflow vulnerability (CVE-2023-7024) actively exploited in the wild via crafted HTML pages.
2022-06-08 CVE-2016-5198 high A Chromium V8 out-of-bounds memory vulnerability enabled remote code execution in multiple browsers, including those used within the DIB, and was actively exploited in the wild.
2021-11-03 CVE-2021-38000 high A Chromium input validation flaw allowed attackers to force browsers to navigate to malicious URLs via crafted HTML pages.
2021-11-03 CVE-2020-16017 high A use-after-free vulnerability in Google Chrome allowed sandbox escapes via crafted HTML pages after the renderer process was compromised.
2021-11-03 CVE-2021-38003 high A memory corruption bug in Google Chromium V8's JSON.stringify function leaked internal data to script code, causing corruption across multiple Chromium-based browsers.
2021-11-03 CVE-2020-16013 high A heap corruption vulnerability in Google Chromium V8 allowed remote attackers to exploit crafted HTML pages, affecting multiple Chromium-based browsers.
2026-06-30 CVE-2026-14104 critical Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
SENTIMENT · TRUSTED SOURCES
synthesisneutral-0.20
Facts-only sources show no vendor condemnation
synthesissevere-fallout-0.70
synthesisnegative-0.40
Acknowledged vulnerability, broad impact.
synthesissevere-fallout-0.80
Critical vulnerability in widely used engine warrants immediate patching and public disclosure.
synthesisnegative-0.60
Acknowledged vulnerability with potential for serious impact.
synthesisnegative-0.60
Acknowledged vulnerability, but no strong condemnation.
synthesissevere-fallout-0.70
Widespread acknowledgement of the vulnerability and its potential impact, with no positive commentary.
synthesissevere-fallout-0.70
Widespread acknowledgement of the vulnerability and its potential impact, with no indication of praise or mitigation efforts by Google.
synthesisnegative-0.40
Acknowledged vulnerability, broad impact noted.
synthesisnegative-0.50
Acknowledged, but no strong condemnation.
synthesissevere-fallout-0.80
Critical vulnerability affecting major browser ecosystem
synthesissevere-fallout-0.70
Widespread acknowledgement of the vulnerability and its impact, with no positive commentary.
synthesisnegative-0.40
Acknowledged vulnerability, but no strong condemnation.
synthesissevere-fallout-0.80
Google's V8 vulnerability was widely flagged as critical, impacting multiple major browsers and triggering immediate remediation demands from security vendors and CISA.
synthesisnegative-0.50
Acknowledged vulnerability, broad impact.
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
Widespread acknowledgement of exploitation and inclusion in authoritative lists indicates significant negative impact.
synthesissevere-fallout-0.70
Widespread acknowledgement of a significant vulnerability with potential for exploitation, impacting multiple browsers and raising concerns about Google's security practices.
synthesisnegative-0.50
Acknowledged vulnerability, but no significant condemnation.
synthesisnegative-0.40
Acknowledged vulnerability, potential for broad impact.
synthesissevere-fallout-0.70
Significant fallout due to widespread impact and CISA's designation as actively exploited.
synthesisnegative-0.60
Significant security flaw with potential for serious exploitation.
xposedornot.com ↗severe-fallout+0.00
No mention of Google or the vulnerability.
cooey ↗negative-0.40
Neutral reporting of facts.
"Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption."
www.mirror.co.uk ↗severe-fallout+0.00
No mention of Google or the vulnerability.
cooey ↗negative-0.60
Neutral reporting of technical details.
"Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page."
cybersecuritynews.com ↗severe-fallout+0.00
No mention of Google or the vulnerability.
cvefeed.io ↗severe-fallout-0.90
Strongly negative; inclusion in CISA KEV catalog signifies active exploitation.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited."
cooey ↗severe-fallout-0.80
Neutral reporting, but highlighting the broad impact.
"This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera."
www.hipaajournal.com ↗severe-fallout+0.00
No mention of Google or the vulnerability.
FEDRAMP CATALOG PRODUCTS · 2
Open questions: Google's remediation timeline for critical vulnerabilities · Impact of these vulnerabilities on CMMC compliance
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:09:26.742840+00:00