Skip to main content
← CVE Tracker

Vendor

Google

148 articles

Abusing Google DoubleClick for DesckVB RAT Delivery — Detection Guide
HIGH
Threat Intel

Abusing Google DoubleClick for DesckVB RAT Delivery — Detection Guide

A new malspam campaign leverages Google DoubleClick redirects to bypass security filters and distribute DesckVB RAT, highlighting trust-based evasion tactics.

Runtime Rebel Intel
4 min read · Jun 3, 2026
Google Gemini Hijacked on Android via Poisoned Notifications
HIGH
Vulnerabilities

Google Gemini Hijacked on Android via Poisoned Notifications

Researchers demonstrate how WhatsApp and Slack notifications can trigger indirect prompt injection in Google Gemini, leading to memory poisoning.

Runtime Rebel Intel
4 min read · Jun 3, 2026
Google Gemini Indirect Prompt Injection via Malicious Notifications
MEDIUM
Vulnerabilities

Google Gemini Indirect Prompt Injection via Malicious Notifications

Security researchers demonstrate how malicious notifications can manipulate Google Gemini's voice assistant to perform unauthorized tasks or exfiltrate data.

Runtime Rebel Intel
4 min read · Jun 3, 2026
TH
MEDIUM
Threat Intel

Google Android Scam Detection: Real-Time AI Defense Against Fraud

Google introduces AI-powered Scam Detection for Android, utilizing on-device Gemini Nano to identify fraud patterns and protect users from voice-based phishing.

Runtime Rebel Intel
4 min read · Jun 3, 2026
CVE-2025-48595: Android June 2026 Update Patches Exploited Zero-Day
HIGH
Vulnerabilities

CVE-2025-48595: Android June 2026 Update Patches Exploited Zero-Day

Google's June 2026 security update fixes 124 vulnerabilities, including CVE-2025-48595, a zero-day privilege escalation flaw under active exploitation.

Runtime Rebel Intel
4 min read · Jun 2, 2026
VU
CRITICAL
Vulnerabilities

Android June 2024 Update: CVE-2024-32896 Zero-Day Exploit Patched

Google fixes 124 vulnerabilities including an actively exploited Pixel firmware zero-day and critical RCE flaws in the June 2024 Android security update.

Runtime Rebel Intel
4 min read · Jun 2, 2026
ID
MEDIUM
Identity & Access

Google Chrome DBSC: Preventing Account Takeover via Cookie Theft

Google Chrome rolls out Device Bound Session Credentials (DBSC) to protect users from session hijacking by cryptographically binding cookies to hardware.

Runtime Rebel Intel
3 min read · May 29, 2026
GlassWorm Malware Takedown: Disruption of Developer Supply Chain C2
HIGH
Supply Chain

GlassWorm Malware Takedown: Disruption of Developer Supply Chain C2

CrowdStrike, Google, and Shadowserver disrupt the GlassWorm malware C2 infrastructure, halting a persistent developer-focused supply chain attack campaign.

Runtime Rebel Intel
4 min read · May 27, 2026
GCP API Keys Remain Active Post-Deletion: A 23-Minute Security Flaw
HIGH
Identity & Access

GCP API Keys Remain Active Post-Deletion: A 23-Minute Security Flaw

A security researcher found Google Cloud Platform (GCP) API keys stay active for 23 minutes post-deletion, posing a significant risk.

Runtime Rebel Intel
5 min read · May 21, 2026
VU
HIGH
Vulnerabilities

Chromium RCE Risk: Unfixed Flaw Allows Background JavaScript

Google accidentally exposed details of an unfixed Chromium flaw. This enables RCE via persistent background JavaScript execution, affecting many browsers.

Runtime Rebel Intel
4 min read · May 21, 2026
SHub Reaper Stealer Backdoors macOS via Spoofed Apps
HIGH
Malware

SHub Reaper Stealer Backdoors macOS via Spoofed Apps

SHub Reaper stealer targets macOS, using fake Google, Microsoft, Apple, WeChat, and Miro installers for Apple script-based execution and backdooring.

Runtime Rebel Intel
5 min read · May 19, 2026
VU
HIGH
Vulnerabilities

Chrome 148 Update: Patching Critical Use-After-Free Vulnerabilities

Google releases Chrome 148 addressing critical-severity use-after-free vulnerabilities.

Runtime Rebel Intel
3 min read · May 15, 2026
VU
HIGH
Vulnerabilities

Pixel 10 0-Click Exploit Chain: Re-Targeting CVE-2025-54957 for Root

Analysis of a zero-click exploit chain targeting the Google Pixel 10, achieving root via an adapted Dolby vulnerability (CVE-2025-54957). Critical threat. Patch now.

Runtime Rebel Intel
4 min read · May 13, 2026
Android Intrusion Logging: Enhancing Spyware Forensics for High-Risk Users
INFO
Threat Intel

Android Intrusion Logging: Enhancing Spyware Forensics for High-Risk Users

Google introduces Intrusion Logging for Android to capture persistent forensic data, aiding the detection of sophisticated spyware and state-sponsored attacks.

Runtime Rebel Intel
4 min read · May 13, 2026
AI-Developed Zero-Day 2FA Bypass: Analyzing Google's Disclosure
HIGH
Threat Intel

AI-Developed Zero-Day 2FA Bypass: Analyzing Google's Disclosure

Google identifies the first in-the-wild zero-day exploit for 2FA bypass developed using AI, signaling a shift in cybercriminal vulnerability discovery.

Runtime Rebel Intel
3 min read · May 11, 2026
VU
INFO
Vulnerabilities

Google’s Big Sleep AI Agent Discovers Real-World SQLite Zero-Day

Google Project Zero and DeepMind’s Big Sleep agent identifies an exploitable stack-based buffer underflow in SQLite, marking a shift in AI vulnerability discovery.

Runtime Rebel Intel
4 min read · May 11, 2026
VU
HIGH
Vulnerabilities

CVE-2024-45785: AI-Generated Zero-Day Exploit Targets BigTree CMS

Google's Threat Intelligence Group discovered a zero-day in BigTree CMS exploited via AI-generated code. Update to version 4.4.16 to prevent remote execution.

Runtime Rebel Intel
3 min read · May 11, 2026
TH
HIGH
Threat Intel

Claude.ai Malvertising: How Attackers Abuse Shared Chats for macOS Malware

Threat actors are leveraging Google Ads and legitimate Claude.ai shared chats to distribute macOS infostealers, effectively bypassing traditional web filters.

Runtime Rebel Intel
3 min read · May 10, 2026
7.3M Downloads: Analyzing Fraudulent Android Call History Apps
HIGH
Threat Intel

7.3M Downloads: Analyzing Fraudulent Android Call History Apps

Researchers discover 28 fraudulent Android apps on the Google Play Store that trick millions of users into expensive, fraudulent subscriptions.

Runtime Rebel Intel
4 min read · May 8, 2026
Google Chrome ABE Bypass: Heightened Infostealer Threat
HIGH
Threat Intel

Google Chrome ABE Bypass: Heightened Infostealer Threat

VoidStealer Trojan authors bypass Google Chrome's App-Bound Encryption (ABE), enabling infostealers to exfiltrate cookies and credentials from users.

Runtime Rebel Intel
5 min read · May 7, 2026
TH
HIGH
Threat Intel

Google Ads Phishing Campaign Targets GoDaddy ManageWP Users

A persistent phishing campaign leverages malicious Google Ads to steal GoDaddy ManageWP credentials, risking extensive WordPress site compromises.

Runtime Rebel Intel
4 min read · May 7, 2026
Google Android Binary Transparency: Defending Against Supply Chain Attacks
INFO
Supply Chain

Google Android Binary Transparency: Defending Against Supply Chain Attacks

Google expands Binary Transparency to Android apps, providing a public ledger to verify app integrity and mitigate risks of mobile supply chain attacks.

Runtime Rebel Intel
4 min read · May 6, 2026
Defeating Persistent OAuth Token Risks in Google and Microsoft Apps
HIGH
Identity & Access

Defeating Persistent OAuth Token Risks in Google and Microsoft Apps

Learn how persistent OAuth tokens create backdoors in AI tools and productivity apps. Discover strategies to detect and remediate long-lived token exposure.

Runtime Rebel Intel
4 min read · May 5, 2026
MA
HIGH
Malware

DarkSword: Analyzing the GTIG iOS Full-Chain Zero-Day Exploit

Google Threat Intelligence Group uncovers DarkSword, a sophisticated iOS exploit chain leveraging multiple zero-days for state-sponsored surveillance.

Runtime Rebel Intel
3 min read · May 5, 2026