# Google vulnerabilities & exploitation

**CISA KEV**

> As of 2026-10-05, Threadlinqs tracks 99 Google CVEs, 18 in the CISA Known Exploited Vulnerabilities catalog, linked to 326 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 99 Google CVEs published between 2021-01-15 and 2026-09-15. The busiest month was 2026-07 (31 new CVEs). 18 of them (18%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 60 of 99 tracked Google CVEs.

- [CVE-2021-38003](https://intel.threadlinqs.com/cve/CVE-2021-38003) — HIGH 8.8 · KEV · EPSS 68.3% · 2021-11-23
- [CVE-2023-2033](https://intel.threadlinqs.com/cve/CVE-2023-2033) — HIGH 8.8 · KEV · EPSS 25.2% · 2023-04-14
- [CVE-2021-37976](https://intel.threadlinqs.com/cve/CVE-2021-37976) — MEDIUM 6.5 · KEV · EPSS 7.7% · 2021-10-08
- [CVE-2021-37973](https://intel.threadlinqs.com/cve/CVE-2021-37973) — CRITICAL 9.6 · KEV · EPSS 6.5% · 2021-10-08
- [CVE-2021-38000](https://intel.threadlinqs.com/cve/CVE-2021-38000) — MEDIUM 6.1 · KEV · EPSS 4.5% · 2021-11-23
- [CVE-2026-5281](https://intel.threadlinqs.com/cve/CVE-2026-5281) — HIGH 8.8 · KEV · EPSS 3.3% · 2026-04-01
- [CVE-2026-87491](https://intel.threadlinqs.com/cve/CVE-2026-87491) — HIGH 8.8 · KEV · EPSS 3.1% · 2026-09-09
- [CVE-2023-3079](https://intel.threadlinqs.com/cve/CVE-2023-3079) — HIGH 8.8 · KEV · EPSS 2.1% · 2023-06-05
- [CVE-2021-1048](https://intel.threadlinqs.com/cve/CVE-2021-1048) — HIGH 7.8 · KEV · EPSS 1.3% · 2021-12-15
- [CVE-2026-85046](https://intel.threadlinqs.com/cve/CVE-2026-85046) — HIGH 8.8 · KEV · EPSS 1.2% · 2026-09-03
- [CVE-2024-7971](https://intel.threadlinqs.com/cve/CVE-2024-7971) — CRITICAL 9.6 · KEV · EPSS 1% · 2024-08-21
- [CVE-2025-6554](https://intel.threadlinqs.com/cve/CVE-2025-6554) — HIGH 8.1 · KEV · EPSS 0.9% · 2025-06-30
- [CVE-2025-14174](https://intel.threadlinqs.com/cve/CVE-2025-14174) — HIGH 8.8 · KEV · EPSS 0.9% · 2025-12-12
- [CVE-2023-2136](https://intel.threadlinqs.com/cve/CVE-2023-2136) — CRITICAL 9.6 · KEV · EPSS 0.7% · 2023-04-19
- [CVE-2026-3910](https://intel.threadlinqs.com/cve/CVE-2026-3910) — HIGH 8.8 · KEV · EPSS 0.6% · 2026-03-13
- [CVE-2025-48543](https://intel.threadlinqs.com/cve/CVE-2025-48543) — HIGH 7.5 · KEV · EPSS 0.3% · 2025-09-04
- [CVE-2026-3909](https://intel.threadlinqs.com/cve/CVE-2026-3909) — HIGH 8.8 · KEV · EPSS 0.3% · 2026-03-13
- [CVE-2026-2441](https://intel.threadlinqs.com/cve/CVE-2026-2441) — HIGH 8.8 · KEV · EPSS 0.3% · 2026-02-13
- [CVE-2020-16040](https://intel.threadlinqs.com/cve/CVE-2020-16040) — MEDIUM 6.5 · EPSS 99.6% · 2021-01-08
- [CVE-2026-22104](https://intel.threadlinqs.com/cve/CVE-2026-22104) — CRITICAL 9.8 · EPSS 91.3% · 2026-02-20
- [CVE-2026-22107](https://intel.threadlinqs.com/cve/CVE-2026-22107) — HIGH 8.4 · EPSS 56.8% · 2026-02-20
- [CVE-2026-22112](https://intel.threadlinqs.com/cve/CVE-2026-22112) — HIGH 7.8 · EPSS 43.1% · 2026-02-20
- [CVE-2026-87464](https://intel.threadlinqs.com/cve/CVE-2026-87464) — CRITICAL 9.6 · EPSS 0.6% · 2026-09-09
- [CVE-2026-10882](https://intel.threadlinqs.com/cve/CVE-2026-10882) — HIGH 8.8 · EPSS 0.5% · 2026-06-04
- [CVE-2026-85047](https://intel.threadlinqs.com/cve/CVE-2026-85047) — CRITICAL 9.6 · EPSS 0.5% · 2026-09-03
- [CVE-2026-87438](https://intel.threadlinqs.com/cve/CVE-2026-87438) — CRITICAL 9.6 · EPSS 0.5% · 2026-09-09
- [CVE-2026-16806](https://intel.threadlinqs.com/cve/CVE-2026-16806) — HIGH 8.8 · EPSS 0.4% · 2026-07-23
- [CVE-2026-87481](https://intel.threadlinqs.com/cve/CVE-2026-87481) — HIGH 8.3 · EPSS 0.4% · 2026-09-09
- [CVE-2026-10881](https://intel.threadlinqs.com/cve/CVE-2026-10881) — CRITICAL 9.6 · EPSS 0.4% · 2026-06-04
- [CVE-2026-12442](https://intel.threadlinqs.com/cve/CVE-2026-12442) — HIGH 8.8 · EPSS 0.4% · 2026-06-17
- [CVE-2026-16805](https://intel.threadlinqs.com/cve/CVE-2026-16805) — HIGH 8.8 · EPSS 0.3% · 2026-07-23
- [CVE-2026-12440](https://intel.threadlinqs.com/cve/CVE-2026-12440) — CRITICAL 9.6 · EPSS 0.3% · 2026-06-17
- [CVE-2026-12439](https://intel.threadlinqs.com/cve/CVE-2026-12439) — HIGH 8.8 · EPSS 0.3% · 2026-06-17
- [CVE-2026-15764](https://intel.threadlinqs.com/cve/CVE-2026-15764) — HIGH 7.5 · EPSS 0.3% · 2026-07-14
- [CVE-2026-15765](https://intel.threadlinqs.com/cve/CVE-2026-15765) — HIGH 7.5 · EPSS 0.3% · 2026-07-14
- [CVE-2026-12441](https://intel.threadlinqs.com/cve/CVE-2026-12441) — HIGH 8.8 · EPSS 0.3% · 2026-06-17
- [CVE-2026-16804](https://intel.threadlinqs.com/cve/CVE-2026-16804) — HIGH 8.3 · EPSS 0.3% · 2026-07-23
- [CVE-2026-15903](https://intel.threadlinqs.com/cve/CVE-2026-15903) — EPSS 0.3% · 2026-07-20
- [CVE-2026-12437](https://intel.threadlinqs.com/cve/CVE-2026-12437) — HIGH 8.3 · EPSS 0.3% · 2026-06-17
- [CVE-2026-14430](https://intel.threadlinqs.com/cve/CVE-2026-14430) — HIGH 8.8 · EPSS 0.3% · 2026-07-01
- [CVE-2026-15902](https://intel.threadlinqs.com/cve/CVE-2026-15902) — EPSS 0.3% · 2026-07-20
- [CVE-2026-12438](https://intel.threadlinqs.com/cve/CVE-2026-12438) — HIGH 8.3 · EPSS 0.3% · 2026-06-17
- [CVE-2026-19202](https://intel.threadlinqs.com/cve/CVE-2026-19202) — CRITICAL 9.1 · EPSS 0.3% · 2026-09-22
- [CVE-2026-16807](https://intel.threadlinqs.com/cve/CVE-2026-16807) — HIGH 8.8 · EPSS 0.2% · 2026-07-23
- [CVE-2026-14428](https://intel.threadlinqs.com/cve/CVE-2026-14428) — HIGH 8.3 · EPSS 0.2% · 2026-07-01
- [CVE-2026-15132](https://intel.threadlinqs.com/cve/CVE-2026-15132) — HIGH 8.8 · EPSS 0.2% · 2026-07-08
- [CVE-2026-15901](https://intel.threadlinqs.com/cve/CVE-2026-15901) — EPSS 0.2% · 2026-07-20
- [CVE-2026-14432](https://intel.threadlinqs.com/cve/CVE-2026-14432) — HIGH 8.8 · EPSS 0.2% · 2026-07-01
- [CVE-2026-14416](https://intel.threadlinqs.com/cve/CVE-2026-14416) — CRITICAL 9.6 · EPSS 0.2% · 2026-07-01
- [CVE-2026-14429](https://intel.threadlinqs.com/cve/CVE-2026-14429) — HIGH 8.3 · EPSS 0.2% · 2026-07-01
- [CVE-2026-15900](https://intel.threadlinqs.com/cve/CVE-2026-15900) — EPSS 0.2% · 2026-07-20
- [CVE-2026-15904](https://intel.threadlinqs.com/cve/CVE-2026-15904) — EPSS 0.2% · 2026-07-20
- [CVE-2026-14426](https://intel.threadlinqs.com/cve/CVE-2026-14426) — HIGH 7.5 · EPSS 0.2% · 2026-07-01
- [CVE-2026-14425](https://intel.threadlinqs.com/cve/CVE-2026-14425) — CRITICAL 9.6 · EPSS 0.2% · 2026-07-01
- [CVE-2026-15107](https://intel.threadlinqs.com/cve/CVE-2026-15107) — HIGH 8.8 · EPSS 0.2% · 2026-07-08
- [CVE-2026-14417](https://intel.threadlinqs.com/cve/CVE-2026-14417) — CRITICAL 9.6 · EPSS 0.2% · 2026-07-01
- [CVE-2026-15130](https://intel.threadlinqs.com/cve/CVE-2026-15130) — MEDIUM 4.3 · EPSS 0.2% · 2026-07-08
- [CVE-2026-15131](https://intel.threadlinqs.com/cve/CVE-2026-15131) — MEDIUM 4.3 · EPSS 0.2% · 2026-07-08
- [CVE-2026-16424](https://intel.threadlinqs.com/cve/CVE-2026-16424) — CRITICAL 9.6 · EPSS 0.2% · 2026-07-21
- [CVE-2026-15129](https://intel.threadlinqs.com/cve/CVE-2026-15129) — HIGH 8.8 · EPSS 0.2% · 2026-07-08

## Products affected

Threadlinqs normalises CPE and CNA product records across all 99 CVEs; 18 distinct Google products are affected. The most frequently affected:

- Chrome — 93 CVEs
- Android — 5 CVEs
- Android Kernel (Binder Driver) — 1 CVE
- Android Runtime (ART) — 1 CVE
- Generic Kernel Image (GKI) 5.10 — 1 CVE
- Generic Kernel Image (GKI) 5.15 — 1 CVE
- Generic Kernel Image (GKI) 6.1 — 1 CVE
- Pixel 7 — 1 CVE
- Pixel 7 Pro — 1 CVE
- Pixel 7a — 1 CVE
- Pixel 8 — 1 CVE
- Pixel 8 Pro — 1 CVE
- Pixel 8a — 1 CVE
- Pixel 9 — 1 CVE
- Pixel 9 Pro — 1 CVE
- Pixel 9 Pro Fold — 1 CVE
- Pixel 9 Pro XL — 1 CVE
- mcp-toolbox-sdk-python — 1 CVE

## Threat activity

326 tracked threat campaigns reference Google products or exploit Google CVEs; the 25 most recent are listed.

- [AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app exploitation, and AI-enabled attacker tooling (s1ngularity, PromptLock, JADEPUFFER/ENCFORGE)](https://intel.threadlinqs.com/threat/TL-2026-2880) — HIGH — 2026-10-03
- [Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)](https://intel.threadlinqs.com/threat/TL-2026-2838) — CRITICAL — 2026-10-02
- [Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection](https://intel.threadlinqs.com/threat/TL-2026-2821) — MEDIUM — 2026-10-01
- [Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)](https://intel.threadlinqs.com/threat/TL-2026-2803) — CRITICAL — 2026-09-30
- [RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization](https://intel.threadlinqs.com/threat/TL-2026-2743) — HIGH — 2026-09-28
- [Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)](https://intel.threadlinqs.com/threat/TL-2026-2752) — HIGH — 2026-09-28
- [UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy CLEANGULP Malware](https://intel.threadlinqs.com/threat/TL-2026-2681) — CRITICAL — 2026-09-27
- [The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments](https://intel.threadlinqs.com/threat/TL-2026-2687) — HIGH — 2026-09-27
- [Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection)](https://intel.threadlinqs.com/threat/TL-2026-2707) — MEDIUM — 2026-09-27
- [Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK A26-09-37)](https://intel.threadlinqs.com/threat/TL-2026-2662) — MEDIUM — 2026-09-26
- [Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users](https://intel.threadlinqs.com/threat/TL-2026-2655) — MEDIUM — 2026-09-25
- [Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script](https://intel.threadlinqs.com/threat/TL-2026-2695) — MEDIUM — 2026-09-25
- [RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV App](https://intel.threadlinqs.com/threat/TL-2026-2625) — HIGH — 2026-09-23
- [Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials](https://intel.threadlinqs.com/threat/TL-2026-2626) — MEDIUM — 2026-09-23
- [ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize Organization Owner](https://intel.threadlinqs.com/threat/TL-2026-2629) — CRITICAL — 2026-09-23
- [Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass Disinformation, Malvertising, and Cryptojacking](https://intel.threadlinqs.com/threat/TL-2026-2631) — HIGH — 2026-09-23
- [ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting Panel](https://intel.threadlinqs.com/threat/TL-2026-2621) — MEDIUM — 2026-09-22
- [Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluation](https://intel.threadlinqs.com/threat/TL-2026-2607) — MEDIUM — 2026-09-21
- [RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs, and MFA Codes](https://intel.threadlinqs.com/threat/TL-2026-2592) — HIGH — 2026-09-20
- [AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and PROMPTSTEAL/LAMEHUG (APT28)](https://intel.threadlinqs.com/threat/TL-2026-2559) — MEDIUM — 2026-09-18
- [CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2570) — CRITICAL — 2026-09-18
- [KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious 'AVSync' Extension](https://intel.threadlinqs.com/threat/TL-2026-2544) — HIGH — 2026-09-16
- [KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to Steal Brazilian Bank Credentials](https://intel.threadlinqs.com/threat/TL-2026-2525) — HIGH — 2026-09-15
- [PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network (CVE-2020-16040)](https://intel.threadlinqs.com/threat/TL-2026-2527) — HIGH — 2026-09-15
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — CRITICAL — 2026-09-13

## Threat actors targeting Google

Named threat actors attributed to campaigns that involve Google products or CVEs, with the number of linked campaigns:

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 7 campaigns
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 7 campaigns
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 6 campaigns
- [UNC2814](https://intel.threadlinqs.com/actor/UNC2814) — 4 campaigns
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 3 campaigns
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 3 campaigns
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 3 campaigns
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 3 campaigns
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 3 campaigns
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2 campaigns
- [BlackSuit affiliate](https://intel.threadlinqs.com/actor/BlackSuit%20affiliate) — 2 campaigns
- [Bling Libra](https://intel.threadlinqs.com/actor/Bling%20Libra) — 2 campaigns

## How to prioritise Google patching

This order follows the data Threadlinqs holds for Google, not a generic severity checklist:

- 18 of 99 Google CVEs (18%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2021-38003](https://intel.threadlinqs.com/cve/CVE-2021-38003), [CVE-2023-2033](https://intel.threadlinqs.com/cve/CVE-2023-2033), [CVE-2021-37976](https://intel.threadlinqs.com/cve/CVE-2021-37976).
- Outside KEV, the highest EPSS scores are [CVE-2020-16040](https://intel.threadlinqs.com/cve/CVE-2020-16040) (99.6%), [CVE-2026-22104](https://intel.threadlinqs.com/cve/CVE-2026-22104) (91.3%), [CVE-2026-22107](https://intel.threadlinqs.com/cve/CVE-2026-22107) (56.8%).
- 16 CVEs score Critical and 58 High on CVSS v3 (maximum 9.8, average 8.1); sequence these after KEV and high-EPSS items.
- 6 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/google
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
