Skip to main content
← CVE Tracker

Vendor

Google

169 articles

Advertisement

ClickFix Variant Leverages Google API for Crypto Theft
MEDIUM
Threat Intel

ClickFix Variant Leverages Google API for Crypto Theft

A ClickFix social engineering variant abuses Google Visualization API and Google Sheets for C2, injecting web skimmers into browsers for cryptocurrency theft.

Runtime Rebel Intel
4 min read · Sep 8, 2026
INFO
Threat Intel

GTIG AI Threat Tracker: Evolution of Adversarial Agentic AI

Google Threat Intelligence Group tracks threat actors shifting to agentic AI, targeting proprietary models, and abusing open source software.

Runtime Rebel Intel
4 min read · Sep 8, 2026
CRITICAL
Vulnerabilities

Chrome Zero-Day CVE-2026-85046 Actively Exploited: Patch Now

Google released an urgent update for a critical Chrome zero-day, CVE-2026-85046, actively exploited in V8 engine type confusion attacks.

Runtime Rebel Intel
4 min read · Sep 4, 2026
Google, Anthropic, and OpenAI Launch Cyber AI Models and Safeguards
INFO
Threat Intel

Google, Anthropic, and OpenAI Launch Cyber AI Models and Safeguards

Google, Anthropic, and OpenAI unveil advanced cybersecurity AI models like Gemini 3.8 Flash Cyber, focusing on defense and strict access controls.

Runtime Rebel Intel
3 min read · Sep 3, 2026
LOW
Threat Intel

Microsoft Defender Blocks Legitimate Google Search Links

Microsoft Defender for Office 365's Safe Links feature is incorrectly flagging legitimate Google search results as malicious, blocking user access and generating alerts.

Runtime Rebel Intel
4 min read · Sep 2, 2026
MEDIUM
Malware

ToxicPanda 2.0 Android Malware Abuses Wireless ADB and VPN

ToxicPanda 2.0 Android malware uses VPN permissions to block Google Play and abuses Wireless ADB to gain shell access and deploy overlays.

Runtime Rebel Intel
3 min read · Aug 23, 2026
Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage
MEDIUM
Threat Intel

Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage

Google Threat Intelligence reports three suspected Russian groups using OAuth phishing, Google app passwords, and WhatsApp device linking to hijack accounts.

Runtime Rebel Intel
3 min read · Aug 23, 2026
MEDIUM
Threat Intel

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

Researchers discover cryptographic context injection, a novel technique bypassing AI safety filters in xAI Grok and Google Gemini using encryption.

Runtime Rebel Intel
3 min read · Aug 22, 2026
MEDIUM
Threat Intel

Russian Threat Clusters Target Academia and Government via Auth Abuse

Google Threat Intelligence Group tracks three Russian cyber espionage clusters abusing legitimate authentication flows and app passwords.

Runtime Rebel Intel
3 min read · Aug 20, 2026
HIGH
Vulnerabilities

Chrome, Firefox, Thunderbird Updates Patch Dozens of High-Severity Flaws

Google and Mozilla release urgent updates for Chrome 151, Firefox 154, and Thunderbird 154, addressing critical and high-severity vulnerabilities including RCE.

Runtime Rebel Intel
4 min read · Aug 19, 2026
INFO
Threat Intel

Agentic Source Code Review: Scaling Vulnerability Discovery with AI

Learn how Google Mandiant uses the Agentic Vulnerability Discovery Harness to accelerate secure code review and find critical flaws at scale.

Runtime Rebel Intel
3 min read · Aug 18, 2026
INFO
Threat Intel

Google Cloud Post-Quantum Roadmap Targets 2029 Readiness

Google Cloud updates its roadmap for post-quantum cryptography (PQC) migration, aiming for full infrastructure readiness by 2029, addressing future quantum threats.

Runtime Rebel Intel
3 min read · Aug 15, 2026
HIGH
Threat Intel

Modern Google Workspace Attack Chain: OAuth & AI Agent Risks

The modern Google Workspace attack chain exploits OAuth grants, not just email. Understand how attackers and AI agents compromise accounts and secure your environment.

Runtime Rebel Intel
4 min read · Aug 15, 2026
LLM API Flaw Exposes Secrets in OpenAI, Anthropic, Google Traces
HIGH
Vulnerabilities

LLM API Flaw Exposes Secrets in OpenAI, Anthropic, Google Traces

A flaw in OpenAI, Anthropic, and Google AI APIs allowed researchers to recover hidden reasoning, API keys, and passwords from exposed session logs.

Runtime Rebel Intel
4 min read · Aug 13, 2026
HIGH
Vulnerabilities

Chrome 151 Update Patches 41 Critical, High-Severity Flaws

Google's Chrome 151 update addresses 41 critical and high-severity vulnerabilities, including memory safety bugs potentially leading to RCE.

Runtime Rebel Intel
4 min read · Aug 9, 2026
HIGH
Vulnerabilities

Pixel 9 Zero-Click RCE: Exploiting Dolby Unified Decoder

Project Zero details a zero-click exploit chain targeting Google Pixel 9 via the Dolby Unified Decoder, leading to arbitrary code execution.

Runtime Rebel Intel
3 min read · Aug 8, 2026
HIGH
Vulnerabilities

Pixel 9 0-Click Sandbox Escape: BigWave UAF to Kernel R/W

A critical 0-click exploit chain targets Google Pixel 9 devices, leveraging a Use-After-Free in the BigWave driver for kernel arbitrary read/write.

Runtime Rebel Intel
4 min read · Aug 8, 2026
MEDIUM
Threat Intel

UNC6671 Rebrands: Multi-Brand Vishing and Cloud Extortion

Google Threat Intelligence Group tracks UNC6671 shifting through Redact, Pink, Helix, and Falcon extortion brands while targeting cloud environments.

Runtime Rebel Intel
3 min read · Aug 7, 2026
MEDIUM
Threat Intel

Pass-ta-key Attacks Hijack Google-Synced Passkeys on Windows

Researchers uncover Pass-ta-key attack methods that allow malware to hijack passkey-protected accounts on Windows without user interaction.

Runtime Rebel Intel
3 min read · Aug 5, 2026
Firebase Misconfiguration in tl;dv AI Tool Exposes Sensitive Meeting Data
HIGH
Vulnerabilities

Firebase Misconfiguration in tl;dv AI Tool Exposes Sensitive Meeting Data

A Google Firebase misconfiguration in the tl;dv AI meeting tool allows unauthorized access to sensitive government and corporate video call information.

Runtime Rebel Intel
4 min read · Aug 4, 2026
Greatness PhaaS Adds Device Code Phishing for MFA Bypass
HIGH
Threat Intel

Greatness PhaaS Adds Device Code Phishing for MFA Bypass

Greatness PhaaS now supports device code phishing, abusing OAuth 2.0 to bypass MFA and seize accounts on Microsoft 365, Google Workspace, and more.

Runtime Rebel Intel
5 min read · Aug 4, 2026
HIGH
Data Breach

Claude AI Chats Exposed on Google: Personal Data and Crypto Keys At Risk

Sensitive personal data, including cryptocurrency wallet keys and medical information, from Anthropic's Claude AI chats are searchable on Google.

Runtime Rebel Intel
5 min read · Aug 4, 2026
HIGH
Vulnerabilities

Google ADK for Python RCE: Agent-to-Agent Attacks Expose Secrets

Pillar Security uncovered agent-to-agent RCE flaws in Google's ADK for Python, allowing secret exposure and PR tampering, risking supply chain integrity.

Runtime Rebel Intel
5 min read · Aug 4, 2026
LOW
Threat Intel

Google Chrome Blocks Malicious New Tab Hijacker Extensions on Unmanaged Devices

Google Chrome will soon block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged Windows and macOS devices.

Runtime Rebel Intel
4 min read · Aug 2, 2026