Exploitation timeline
Threadlinqs has recorded 99 Google CVEs published between and . The busiest month was 2026-07 (31 new CVEs). 18 of them (18%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 60 of 99 tracked Google CVEs.
- CVE-2021-38003high 8.8KEVEPSS 68.3%
- CVE-2023-2033high 8.8KEVEPSS 25.2%
- CVE-2021-37976medium 6.5KEVEPSS 7.7%
- CVE-2021-37973critical 9.6KEVEPSS 6.5%
- CVE-2021-38000medium 6.1KEVEPSS 4.5%
- CVE-2026-5281high 8.8KEVEPSS 3.3%
- CVE-2026-87491high 8.8KEVEPSS 3.1%
- CVE-2023-3079high 8.8KEVEPSS 2.1%
- CVE-2021-1048high 7.8KEVEPSS 1.3%
- CVE-2026-85046high 8.8KEVEPSS 1.2%
- CVE-2024-7971critical 9.6KEVEPSS 1%
- CVE-2025-6554high 8.1KEVEPSS 0.9%
- CVE-2025-14174high 8.8KEVEPSS 0.9%
- CVE-2023-2136critical 9.6KEVEPSS 0.7%
- CVE-2026-3910high 8.8KEVEPSS 0.6%
- CVE-2025-48543high 7.5KEVEPSS 0.3%
- CVE-2026-3909high 8.8KEVEPSS 0.3%
- CVE-2026-2441high 8.8KEVEPSS 0.3%
- CVE-2020-16040medium 6.5EPSS 99.6%
- CVE-2026-22104critical 9.8EPSS 91.3%
- CVE-2026-22107high 8.4EPSS 56.8%
- CVE-2026-22112high 7.8EPSS 43.1%
- CVE-2026-87464critical 9.6EPSS 0.6%
- CVE-2026-10882high 8.8EPSS 0.5%
- CVE-2026-85047critical 9.6EPSS 0.5%
- CVE-2026-87438critical 9.6EPSS 0.5%
- CVE-2026-16806high 8.8EPSS 0.4%
- CVE-2026-87481high 8.3EPSS 0.4%
- CVE-2026-10881critical 9.6EPSS 0.4%
- CVE-2026-12442high 8.8EPSS 0.4%
- CVE-2026-16805high 8.8EPSS 0.3%
- CVE-2026-12440critical 9.6EPSS 0.3%
- CVE-2026-12439high 8.8EPSS 0.3%
- CVE-2026-15764high 7.5EPSS 0.3%
- CVE-2026-15765high 7.5EPSS 0.3%
- CVE-2026-12441high 8.8EPSS 0.3%
- CVE-2026-16804high 8.3EPSS 0.3%
- CVE-2026-15903EPSS 0.3%
- CVE-2026-12437high 8.3EPSS 0.3%
- CVE-2026-14430high 8.8EPSS 0.3%
- CVE-2026-15902EPSS 0.3%
- CVE-2026-12438high 8.3EPSS 0.3%
- CVE-2026-19202critical 9.1EPSS 0.3%
- CVE-2026-16807high 8.8EPSS 0.2%
- CVE-2026-14428high 8.3EPSS 0.2%
- CVE-2026-15132high 8.8EPSS 0.2%
- CVE-2026-15901EPSS 0.2%
- CVE-2026-14432high 8.8EPSS 0.2%
- CVE-2026-14416critical 9.6EPSS 0.2%
- CVE-2026-14429high 8.3EPSS 0.2%
- CVE-2026-15900EPSS 0.2%
- CVE-2026-15904EPSS 0.2%
- CVE-2026-14426high 7.5EPSS 0.2%
- CVE-2026-14425critical 9.6EPSS 0.2%
- CVE-2026-15107high 8.8EPSS 0.2%
- CVE-2026-14417critical 9.6EPSS 0.2%
- CVE-2026-15130medium 4.3EPSS 0.2%
- CVE-2026-15131medium 4.3EPSS 0.2%
- CVE-2026-16424critical 9.6EPSS 0.2%
- CVE-2026-15129high 8.8EPSS 0.2%
Products affected
Threadlinqs normalises CPE and CNA product records across all 99 CVEs; 18 distinct Google products are affected. The most frequently affected:
- Chrome 93 CVEs
- Android 5 CVEs
- Android Kernel (Binder Driver) 1 CVE
- Android Runtime (ART) 1 CVE
- Generic Kernel Image (GKI) 5.10 1 CVE
- Generic Kernel Image (GKI) 5.15 1 CVE
- Generic Kernel Image (GKI) 6.1 1 CVE
- Pixel 7 1 CVE
- Pixel 7 Pro 1 CVE
- Pixel 7a 1 CVE
- Pixel 8 1 CVE
- Pixel 8 Pro 1 CVE
- Pixel 8a 1 CVE
- Pixel 9 1 CVE
- Pixel 9 Pro 1 CVE
- Pixel 9 Pro Fold 1 CVE
- Pixel 9 Pro XL 1 CVE
- mcp-toolbox-sdk-python 1 CVE
Threat activity
326 tracked threat campaigns reference Google products or exploit Google CVEs; the 25 most recent are listed.
- AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app exploitation, and AI-enabled attacker tooling (s1ngularity, PromptLock, JADEPUFFER/ENCFORGE)HIGH
- Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)CRITICAL
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic RedirectionMEDIUM
- Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)CRITICAL
- RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim PrioritizationHIGH
- Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)HIGH
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy CLEANGULP MalwareCRITICAL
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI EnvironmentsHIGH
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection)MEDIUM
- Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK A26-09-37)MEDIUM
- Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile UsersMEDIUM
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call ScriptMEDIUM
- RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV AppHIGH
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google CredentialsMEDIUM
- ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize Organization OwnerCRITICAL
- Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass Disinformation, Malvertising, and CryptojackingHIGH
- ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting PanelMEDIUM
- Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security EvaluationMEDIUM
- RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs, and MFA CodesHIGH
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and PROMPTSTEAL/LAMEHUG (APT28)MEDIUM
- CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV CatalogCRITICAL
- KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious 'AVSync' ExtensionHIGH
- KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to Steal Brazilian Bank CredentialsHIGH
- PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network (CVE-2020-16040)HIGH
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit MalwareCRITICAL
Threat actors targeting Google
Named threat actors attributed to campaigns that involve Google products or CVEs, with the number of linked campaigns:
How to prioritise Google patching
This order follows the data Threadlinqs holds for Google, not a generic severity checklist:
- 18 of 99 Google CVEs (18%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2021-38003, CVE-2023-2033, CVE-2021-37976.
- Outside KEV, the highest EPSS scores are CVE-2020-16040 (99.6%), CVE-2026-22104 (91.3%), CVE-2026-22107 (56.8%).
- 16 CVEs score Critical and 58 High on CVSS v3 (maximum 9.8, average 8.1); sequence these after KEV and high-EPSS items.
- 6 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.