Skip to main content
← CVE Tracker

Vendor

Google

148 articles

TH
LOW
Threat Intel

Google Chrome Blocks Malicious New Tab Hijacker Extensions on Unmanaged Devices

Google Chrome will soon block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged Windows and macOS devices.

Runtime Rebel Intel
4 min read · Aug 2, 2026
Google Chrome Updates Resolve 1,442 Security Flaws
LOW
Vulnerabilities

Google Chrome Updates Resolve 1,442 Security Flaws

Google Chrome recently addressed 1,442 security flaws across versions 149, 150, and 151. Learn why immediate updates are crucial for user security.

Runtime Rebel Intel
4 min read · Jul 31, 2026
TH
INFO
Threat Intel

Google AI Agent Uncovers 13-Year-Old Chrome Flaw

Google's AI agent harness identified a 13-year-old flaw in Chrome's codebase, highlighting AI's role in vulnerability research and Google's patching efforts.

Runtime Rebel Intel
4 min read · Jul 31, 2026
VU
INFO
Vulnerabilities

AI-Powered Vulnerability Research: Google Patches 1,000+ Chrome Bugs

Google utilizes Big Sleep AI to identify and remediate over 1,000 security vulnerabilities in Chrome releases, signaling a shift in automated bug hunting.

Runtime Rebel Intel
4 min read · Jul 30, 2026
TH
INFO
Threat Intel

Google Unified Threat Actor Naming: TAG and Mandiant Convergence

Google unifies threat actor naming across TAG and Mandiant to streamline attribution and improve intelligence sharing for security operations teams.

Runtime Rebel Intel
3 min read · Jul 28, 2026
Confused Deputy Flaws in Google Cloud & Azure: Admin Bypass
HIGH
Cloud Security

Confused Deputy Flaws in Google Cloud & Azure: Admin Bypass

Analysis of 'Confused Deputy' vulnerabilities across Google Cloud and Microsoft Azure, enabling administrative privilege escalation and access control bypass.

Runtime Rebel Intel
5 min read · Jul 28, 2026
TH
INFO
Threat Intel

Google Threat Intel Adopts Unified Cryptonym Naming for Actors

Google Threat Intelligence Group (GTIG) rolls out a new two-word cryptonym-based naming schema for threat actors, standardizing tracking across platforms for enhanced…

Runtime Rebel Intel
4 min read · Jul 24, 2026
CO
INFO
Compliance

Google Fined €890M: Evaluating Digital Markets Act Compliance Risks

Google faces a $1 billion EU fine for Digital Markets Act breaches. This report analyzes the technical compliance risks for search engines and app stores.

Runtime Rebel Intel
4 min read · Jul 23, 2026
Google Gemini 3.5 Flash Cyber AI: Advanced Vulnerability Management
INFO
Vulnerabilities

Google Gemini 3.5 Flash Cyber AI: Advanced Vulnerability Management

Google launches Gemini 3.5 Flash Cyber, a specialized AI for rapid vulnerability discovery, validation, and patching, available to governments via CodeMender.

Runtime Rebel Intel
4 min read · Jul 21, 2026
Russian-Speaking Hacker Uses Google Gemini CLI for Botnet Control
MEDIUM
Threat Intel

Russian-Speaking Hacker Uses Google Gemini CLI for Botnet Control

Russian-speaking actor bandcampro utilized Google Gemini CLI to automate botnet control and password cracking across compromised dental healthcare systems.

Runtime Rebel Intel
3 min read · Jul 20, 2026
Google Cloud Agentic Defense: Automating AI-Driven Security Response
INFO
Cloud Security

Google Cloud Agentic Defense: Automating AI-Driven Security Response

Google Cloud integrates Wiz and Mandiant capabilities into its new Agentic Defense model, using AI agents to automate complex threat detection workflows.

Runtime Rebel Intel
4 min read · Jul 17, 2026
EU Orders Android 18 to Open AI Hardware Access to Rivals
MEDIUM
Compliance

EU Orders Android 18 to Open AI Hardware Access to Rivals

The EU orders Google to grant rival AI assistants deep hardware access in Android 18, raising concerns over microphone, camera, and screen data privacy.

Runtime Rebel Intel
3 min read · Jul 17, 2026
VU
HIGH
Vulnerabilities

Anthropic Claude Chrome Extension: Malicious AI Action Trigger

A flaw in Anthropic's Claude for Chrome extension enables malicious extensions to trigger AI actions, potentially abusing access to connected services like Gmail, Google…

Runtime Rebel Intel
4 min read · Jul 16, 2026
TH
MEDIUM
Threat Intel

Google Gemini CLI Abused by 'bandcampro' for Botnet Operations

Russian-speaking threat actor 'bandcampro' is leveraging Google's Gemini CLI as a hacking agent and to command a small-scale botnet.

Runtime Rebel Intel
5 min read · Jul 15, 2026
CL
HIGH
Cloud Security

Exposed Cloud Functions: Hardening GCP Serverless Against LFI & RCE

Mandiant identifies exposed serverless functions as initial access points. Learn to harden Google Cloud Run against LFI and RCE with IAM, WAF, and secure SDLC.

Runtime Rebel Intel
6 min read · Jul 15, 2026
ModHeader Extension Pulled Over Dormant Browsing Data Collector
MEDIUM
Supply Chain

ModHeader Extension Pulled Over Dormant Browsing Data Collector

ModHeader, a popular browser extension with 1.6M installs on Chrome and Edge, was pulled by Google and Microsoft after a dormant browsing history collector was found.

Runtime Rebel Intel
4 min read · Jul 13, 2026
VU
CRITICAL
Vulnerabilities

Chrome 150 Update: Patching 27 Vulnerabilities, Critical Use-After-Free Flaws

Google Chrome 150 update patches 27 vulnerabilities, including two critical use-after-free bugs.

Runtime Rebel Intel
4 min read · Jul 9, 2026
VU
HIGH
Vulnerabilities

Dialogflow CX 'Rogue Agent' Bug Enabled AI Conversation Hijacking

A 'Rogue Agent' vulnerability in Google Dialogflow CX could have allowed attackers to silently manipulate AI conversations, exfiltrate data, and compromise multiple…

Runtime Rebel Intel
4 min read · Jul 8, 2026
Phishing Campaign Uses Nested Redirects to Hijack Google Accounts
MEDIUM
Threat Intel

Phishing Campaign Uses Nested Redirects to Hijack Google Accounts

Marketing professionals are being targeted by a sophisticated phishing campaign using nested redirects and fake job offers to compromise Google credentials.

Runtime Rebel Intel
4 min read · Jul 8, 2026
Google Dialogflow CX: Critical Flaw Allows Agent Hijack
HIGH
Vulnerabilities

Google Dialogflow CX: Critical Flaw Allows Agent Hijack

A critical flaw in Google Dialogflow CX allowed attackers with edit rights to one agent to hijack others in the same project, exposing user data.

Runtime Rebel Intel
5 min read · Jul 7, 2026
TH
HIGH
Threat Intel

Google Sues Outsider Enterprise Over Gemini-Powered Phishing-as-a-Service

Google takes legal action against Outsider Enterprise, a Chinese cybercrime network using Gemini AI to automate sophisticated phishing campaigns against global users.

Runtime Rebel Intel
5 min read · Jul 7, 2026
TH
MEDIUM
Threat Intel

Job Interview Phishing Targets Google Accounts of Marketing Professionals

A new phishing campaign impersonates 30+ major brands to lure marketing professionals into fake job interviews, aiming to steal their Google account credentials.

Runtime Rebel Intel
4 min read · Jul 6, 2026
TH
MEDIUM
Threat Intel

Google Disrupts NetNut Malicious Residential Proxy Network

Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.

Runtime Rebel Intel
4 min read · Jul 3, 2026
NetNut (Popa) Residential Proxy Disruption: Impact & Defense
MEDIUM
Threat Intel

NetNut (Popa) Residential Proxy Disruption: Impact & Defense

Google, FBI, and Lumen have disrupted NetNut (Popa), a vast residential proxy network, reducing its pool of compromised home devices by millions.

Runtime Rebel Intel
4 min read · Jul 2, 2026