See how google compares to other vendors in security performance
Accessibility. An authorization issue was addressed with improved state management.
In attpbuildreadbytypevaluecmd of attprotocol.cc , there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Chromium: CVE-2023-2136 Integer overflow in Skia
Chromium: CVE-2023-6345 Integer overflow in Skia
Microsoft Power Platform Connector Spoofing Vulnerability
Chromium: CVE-2024-0517 Out of bounds write in V8
Chromium: CVE-2024-0518 Type Confusion in V8
Chromium: CVE-2024-0519 Out of bounds memory access in V8
Citrix NetScaler ADC and NetScaler Gateway contain a code injection vulnerability that allows for authenticated remote code execution on the management interface with access to NSIP, CLIP, or SNIP.
Chromium: CVE-2024-3159 Out of bounds memory access in V8
Chromium: CVE-2023-4762 Type Confusion in V8
Chromium: CVE-2025-5419 Out of bounds read and write in V8
Chromium: CVE-2025-5068 Use after free in Blink
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
Chromium: CVE-2023-4863 Heap buffer overflow in WebP
Chromium: CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx
Chromium: CVE-2023-2033 Type Confusion in V8
Chromium: CVE-2023-3079 Type Confusion in V8
Chromium: CVE-2023-6350 Out of bounds memory access in libavif
Chromium: CVE-2023-6351 Use after free in libavif
Chromium: CVE-2023-6347 Use after free in Mojo
Chromium: CVE-2023-6348 Type Confusion in Spellcheck
Chromium: CVE-2023-6346 Use after free in WebAudio
In callbackthreadevent of comandroidbluetoothbtserviceAdapterService.cpp, there is a possible memory corruption due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.
Chromium: CVE-2023-7024 Heap buffer overflow in WebRTC
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.