FAIL › dossier
FedRAMP provider · · dossier confidence 20%
Google Chrome is currently under active exploitation due to a cluster of critical sandbox escape and RCE vulnerabilities in core components like V8 and Skia, with multiple patches released in July 2026 to address these high-risk flaws.
PROFILE
CategoryTechnology VendorWhat they doGoogle is a multinational technology company that develops and provides various internet-based services and products, including the Chrome web browser.
Websitehttps://www.google.com ↗
SECURITY POSTURE
Google demonstrates a reactive security posture with a high volume of critical and high-severity vulnerabilities in Chrome, particularly involving sandbox escape and use-after-free flaws in core components like V8, Skia, and ANGLE.
Notable failures
- CVE-2026-14104: Critical RCE in WebAppInstalls
- CVE-2026-13782: Critical Sandbox Escape in Browser
- CVE-2026-13781: Critical Sandbox Escape in Skia
- CVE-2026-13776: Critical Sandbox Escape in Dawn
- CVE-2026-13775: Critical Sandbox Escape in GPU
- CVE-2026-11720: Critical Path Traversal in googleapis/mcp-toolbox
Patterns: Repeated unpatched edge-device RCEs; Sandbox escape via renderer process compromise; Use-after-free vulnerabilities in core rendering components
FAILURE HISTORY · 60
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-03-13 | CVE-2026-3910 | high | Google Chromium V8 allows remote code execution via crafted HTML pages, enabling attackers to bypass sandbox protections. |
| 2022-05-23 | CVE-2019-13720 | high | A use-after-free vulnerability in Google Chrome's WebAudio component allowed remote attackers to exploit heap corruption via a crafted HTML page. |
| 2021-11-03 | CVE-2021-21220 | high | A remote attacker could exploit heap corruption via a crafted HTML page in Google Chromium V8 to execute arbitrary code. |
| 2022-05-23 | CVE-2019-5786 | high | A use-after-free vulnerability in Chrome Blink allowed out-of-bounds memory access via a crafted HTML page and was actively exploited in the wild. |
| 2022-04-11 | CVE-2021-39793 | high | A local privilege escalation vulnerability in Google Pixel devices was actively exploited in the wild, highlighting the risks of unpatched hardware in defense supply chains. |
| 2022-02-15 | CVE-2022-0609 | high | A use-after-free vulnerability in Google Chromium's animation code allowed remote attackers to exploit heap corruption via crafted HTML pages. |
| 2022-01-10 | CVE-2020-6572 | high | A use-after-free vulnerability in Google Chrome's media component allowed remote code execution via a crafted HTML page and was actively exploited in the wild. |
| 2021-11-03 | CVE-2021-21166 | high | A race condition in Google Chromium allows remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-21193 | high | A use-after-free vulnerability in Google Chromium Blink allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-21224 | high | A type confusion vulnerability in Google Chromium V8 allowed remote code execution inside a browser sandbox via a crafted HTML page. |
| 2021-11-03 | CVE-2021-21206 | high | A use-after-free vulnerability in Google Chromium Blink allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-30551 | high | A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-37973 | high | A use-after-free vulnerability in Google Chromium Portals allowed sandbox escapes via crafted HTML pages after the renderer process was compromised. |
| 2021-11-03 | CVE-2021-21148 | high | A heap buffer overflow in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-30632 | high | An out-of-bounds write vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2020-15999 | high | A heap buffer overflow in Google Chrome's FreeType font rendering library was actively exploited in the wild as part of an exploit chain. |
| 2022-04-15 | CVE-2022-1364 | high | A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2022-03-28 | CVE-2022-1096 | high | A type confusion vulnerability in Google's Chromium V8 engine allowed remote attackers to exploit heap corruption via crafted HTML pages. |
| 2021-12-15 | CVE-2021-4102 | high | A use-after-free vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-37975 | high | A use-after-free vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2020-6418 | high | A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-30563 | high | A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-30554 | high | A use-after-free vulnerability in Google Chromium WebGL allowed remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2020-16009 | high | A type confusion vulnerability in Google's Chromium V8 engine allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2026-02-17 | CVE-2026-2441 | high | Chrome rce due to CSS use-after-free |
| 2025-12-12 | CVE-2025-14174 | high | Google Chromium out-of-bounds memory access flaw exploited |
| 2025-11-19 | CVE-2025-13223 | high | Google Chromium V8 heap corruption |
| 2025-09-23 | CVE-2025-10585 | high | Google Chromium V8 had an unpatched type confusion vulnerability actively exploited in the wild |
| 2025-07-22 | CVE-2025-6558 | high | Google Chromium ANGLE and GPU input validation flaw exploited remotely |
| 2025-07-02 | CVE-2025-6554 | high | Google Chromium V8 had a type confusion vulnerability exploited in the wild |
| 2025-06-05 | CVE-2025-5419 | high | Google Chromium V8 OOB Read/Write Vuln exploited |
| 2025-03-27 | CVE-2025-2783 | high | A logic error in Google Chromium's Mojo sandbox allows for potential escape, impacting browsers like Chrome and Edge and actively being exploited in the wild. |
| 2023-11-30 | CVE-2023-6345 | high | A Google Skia integer overflow vulnerability allowed sandbox escape via a malicious file, actively exploited in the wild and impacting Chrome, ChromeOS, Android, and Flutter products. |
| 2023-10-02 | CVE-2023-5217 | high | Google Chromium libvpx heap buffer overflow allows remote code execution. |
| 2023-06-07 | CVE-2023-3079 | high | Google Chromium V8 Type Confusion Vulnerability allows remote code execution. |
| 2023-04-21 | CVE-2023-2136 | high | Google Chrome Skia Integer Overflow Vulnerability |
| 2023-04-17 | CVE-2023-2033 | high | Google Chromium V8 Type Confusion Vulnerability allows remote code execution. |
| 2023-03-30 | CVE-2022-3038 | high | Google Chromium Network Service Use-After-Free Vulnerability exploited remotely |
| 2022-12-05 | CVE-2022-4262 | high | Google Chromium V8 Engine had a type confusion vulnerability actively exploited in the wild |
| 2022-11-28 | CVE-2022-4135 | high | Google Chromium GPU heap buffer overflow allowed remote attacker to escape sandbox |
| 2022-10-28 | CVE-2022-3723 | high | Google Chromium V8 Engine had a type confusion vulnerability actively exploited in the wild |
| 2022-09-08 | CVE-2022-3075 | high | Google Chromium Mojo allows remote attackers to escape the sandbox via a crafted HTML page. |
| 2022-08-18 | CVE-2022-2856 | high | Google Chromium Intents CVE-2022-2856 allows remote code execution via malicious HTML pages |
| 2022-06-27 | CVE-2021-30533 | high | A Chromium PopupBlocker vulnerability allowed attackers to bypass navigation restrictions via crafted iframes, impacting multiple browsers including Chrome and Edge, and actively exploited in the wild. |
| 2022-06-08 | CVE-2018-17463 | high | A Chromium V8 vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers and potentially DIB organizations using them for web access or internal tools. |
| 2022-06-08 | CVE-2017-5030 | high | A memory corruption vulnerability in Google's Chromium V8 engine allowed remote code execution via crafted HTML pages, impacting multiple browsers including Chrome and Edge, and actively exploited in the wild. |
| 2022-06-08 | CVE-2018-17480 | high | A Chromium V8 out-of-bounds write vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers including Chrome and Edge, and is currently being exploited in the wild. |
| 2022-06-08 | CVE-2019-5825 | high | A heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via a crafted HTML page. |
| 2022-06-08 | CVE-2016-1646 | high | A Chromium V8 out-of-bounds read vulnerability was actively exploited, impacting browsers like Chrome and Edge, potentially causing denial of service or other impacts. |
| 2022-06-08 | CVE-2018-6065 | high | A heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via crafted HTML pages. |
| 2021-11-03 | CVE-2021-37976 | high | A remote attacker could extract sensitive data from Chromium browser processes via a crafted HTML page due to an unpatched memory disclosure flaw. |
| 2026-06-09 | CVE-2026-11645 | high | Google Chromium V8 allows remote code execution via crafted HTML pages, enabling sandbox escape and arbitrary code execution. |
| 2024-05-20 | CVE-2024-4947 | high | Google Chromium V8 allows remote code execution via a type confusion vulnerability in a crafted HTML page. |
| 2024-01-02 | CVE-2023-7024 | high | Google Chromium WebRTC suffered a heap buffer overflow vulnerability (CVE-2023-7024) actively exploited in the wild via crafted HTML pages. |
| 2022-06-08 | CVE-2016-5198 | high | A Chromium V8 out-of-bounds memory vulnerability enabled remote code execution in multiple browsers, including those used within the DIB, and was actively exploited in the wild. |
| 2021-11-03 | CVE-2021-38000 | high | A Chromium input validation flaw allowed attackers to force browsers to navigate to malicious URLs via crafted HTML pages. |
| 2021-11-03 | CVE-2020-16017 | high | A use-after-free vulnerability in Google Chrome allowed sandbox escapes via crafted HTML pages after the renderer process was compromised. |
| 2021-11-03 | CVE-2021-38003 | high | A memory corruption bug in Google Chromium V8's JSON.stringify function leaked internal data to script code, causing corruption across multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2020-16013 | high | A heap corruption vulnerability in Google Chromium V8 allowed remote attackers to exploit crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2026-06-30 | CVE-2026-14104 | critical | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) |
SENTIMENT · TRUSTED SOURCES
synthesisneutral-0.20
Facts-only sources show no vendor condemnation
synthesissevere-fallout-0.70
…
synthesisnegative-0.40
Acknowledged vulnerability, broad impact.
synthesissevere-fallout-0.80
Critical vulnerability in widely used engine warrants immediate patching and public disclosure.
synthesisnegative-0.60
Acknowledged vulnerability with potential for serious impact.
synthesisnegative-0.60
Acknowledged vulnerability, but no strong condemnation.
synthesissevere-fallout-0.70
Widespread acknowledgement of the vulnerability and its potential impact, with no positive commentary.
synthesissevere-fallout-0.70
Widespread acknowledgement of the vulnerability and its potential impact, with no indication of praise or mitigation efforts by Google.
synthesisnegative-0.40
Acknowledged vulnerability, broad impact noted.
synthesisnegative-0.50
Acknowledged, but no strong condemnation.
synthesissevere-fallout-0.80
Critical vulnerability affecting major browser ecosystem
synthesissevere-fallout-0.70
Widespread acknowledgement of the vulnerability and its impact, with no positive commentary.
synthesisnegative-0.40
Acknowledged vulnerability, but no strong condemnation.
synthesissevere-fallout-0.80
Google's V8 vulnerability was widely flagged as critical, impacting multiple major browsers and triggering immediate remediation demands from security vendors and CISA.
synthesisnegative-0.50
Acknowledged vulnerability, broad impact.
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
Widespread acknowledgement of exploitation and inclusion in authoritative lists indicates significant negative impact.
synthesissevere-fallout-0.70
Widespread acknowledgement of a significant vulnerability with potential for exploitation, impacting multiple browsers and raising concerns about Google's security practices.
synthesisnegative-0.50
Acknowledged vulnerability, but no significant condemnation.
synthesisnegative-0.40
Acknowledged vulnerability, potential for broad impact.
synthesissevere-fallout-0.70
Significant fallout due to widespread impact and CISA's designation as actively exploited.
synthesisnegative-0.60
Significant security flaw with potential for serious exploitation.
No mention of Google or the vulnerability.
Neutral reporting of facts.
"Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption."
No mention of Google or the vulnerability.
Neutral reporting of technical details.
"Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page."
No mention of Google or the vulnerability.
Strongly negative; inclusion in CISA KEV catalog signifies active exploitation.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited."
Neutral reporting, but highlighting the broad impact.
"This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera."
No mention of Google or the vulnerability.
FEDRAMP CATALOG PRODUCTS · 2
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Google Services (Google Cloud Platform Products and underlying Infrastructure) | Authorized | High |
| Google Workspace | Authorized | High |
DOSSIER SOURCES
- Google CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Chrome CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- CVE Vulnerability Alerts - Daily Security Review · dailysecurityreview.com
Open questions: Google's remediation timeline for critical vulnerabilities · Impact of these vulnerabilities on CMMC compliance
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:09:26.742840+00:00