See how google compares to other vendors in security performance
Chromium: CVE-2025-9866 Inappropriate implementation in Extensions
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.
Cryptographic issue while performing RSA PKCS padding decoding.
Chromium: CVE-2025-10201 Inappropriate implementation in Mojo
Chromium: CVE-2025-10200 Use after free in Serviceworker
Chromium: CVE-2025-10501 Use after free in WebRTC
Chromium: CVE-2025-10500 Use after free in Dawn
Chromium: CVE-2025-10890 Side-channel information leakage in V8
Chromium: CVE-2025-10891 Integer overflow in V8
Chromium: CVE-2025-13042 Inappropriate implementation in V8
In btahfclientcbinit of btahfclientmain.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
In dpc modem, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed
In Modem, there is a possible application crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00628396; Issue ID: MSV-4775.
Chromium: CVE-2025-13639 Inappropriate implementation in WebRTC
Chromium: CVE-2025-13721 Race in v8
Chromium: CVE-2025-13638 Use after free in Media Stream
Chromium: CVE-2025-13635 Inappropriate implementation in Downloads
Chromium: CVE-2025-13631 Inappropriate implementation in Google Updater
Chromium: CVE-2025-13637 Inappropriate implementation in Downloads
Chromium: CVE-2025-13636 Inappropriate implementation in Split View
Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Chromium: CVE-2025-13633 Use after free in Digital Credentials
Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
A vulnerability exists in Google Apigee's JavaCallout policy https://docs.apigee.com/api-platform/reference/policies/java-callout-policy that allows for remote code execution.
It is possible for a user to write a JavaCallout that injected a malicious object into the MessageContext to execute arbitrary Java code and system commands at runtime, leading to unauthorized access to data, lateral movement within the network, and access to backend systems.
The Apigee hybrid versions below have all been updated to protect from this vulnerability: Hybrid1.11.2+ Hybrid1.12.4+ Hybrid1.13.3+ Hybrid1.14.1+ OPDK5202+ OPDK5300+
A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifacts to a Data Fusion instance can execute arbitrary code within the core AppFabric component. This could allow the attacker to gain control over the Data Fusion instance, potentially leading to unauthorized access to sensitive data, modification of data pipelines, and exploration of the underlying infrastructure.
The following CDAP versions include the necessary update to protect against this vulnerability: 6.10.6+ 6.11.1+
Users must immediately upgrade to them, or greater ones, available at: https://github.com/cdapio/cdap-build/releases .
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
Microsoft Edge for Android Information Disclosure Vulnerability
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.