Skip to main content
← CVE Tracker

Vendor

Google

148 articles

VU
HIGH
Vulnerabilities

Android CVE-2026-0073: Critical System RCE Patch Guidance

Google addresses a critical zero-click RCE vulnerability (CVE-2026-0073) in the Android System component. Learn how to mitigate this high-impact security flaw.

Runtime Rebel Intel
3 min read · May 5, 2026
VU
INFO
Vulnerabilities

Google Android VRP 2024 Updates: $1.5M for Pixel Kernel Exploits

Google overhauls its Vulnerability Rewards Programs, increasing payouts for complex Android exploits while devaluing bugs easily identified by AI tools.

Runtime Rebel Intel
3 min read · May 5, 2026
TH
INFO
Threat Intel

US DoD Partners with 7 Tech Giants for Classified AI Integration

The US Department of Defense secures deals with AWS, Google, and OpenAI to integrate AI into classified environments, focusing on operational decision-making.

Runtime Rebel Intel
4 min read · May 3, 2026
AccountDumpling: Vietnamese Phishing Relay Abuses Google AppSheet
HIGH
Threat Intel

AccountDumpling: Vietnamese Phishing Relay Abuses Google AppSheet

A Vietnamese-linked operation dubbed AccountDumpling used Google AppSheet as a phishing relay to compromise 30,000 Facebook accounts for illicit resale.

Runtime Rebel Intel
4 min read · May 1, 2026
VU
INFO
Vulnerabilities

Google Adjusts Bug Bounties: $1.5M Android Reward and AI Shift

Google updates its Vulnerability Reward Program, increasing Android zero-click payouts to $1.5 million while adjusting Chrome rewards amid an AI security surge.

Runtime Rebel Intel
4 min read · May 1, 2026
VU
HIGH
Vulnerabilities

Google Gemini CLI Host Code Execution: Securing AI Developer Tools

Critical security flaw in Google Gemini CLI allows host code execution and supply chain attacks via malicious configurations. Learn how to mitigate.

Runtime Rebel Intel
4 min read · Apr 30, 2026
Gemini CLI Critical RCE Fix: Patching the @google/gemini-cli Flaw
HIGH
Vulnerabilities

Gemini CLI Critical RCE Fix: Patching the @google/gemini-cli Flaw

Google patches a CVSS 10.0 flaw in Gemini CLI tools that allowed unprivileged attackers to execute commands in CI/CD environments via malicious configurations.

Runtime Rebel Intel
3 min read · Apr 30, 2026
TH
MEDIUM
Threat Intel

Malicious AI Prompt Injection Attacks: Google Red Team Insights

Google reports a surge in AI prompt injection attacks, highlighting low-sophistication attempts and strategies for mitigating indirect prompt injection risks.

Runtime Rebel Intel
4 min read · Apr 27, 2026
CL
INFO
Cloud Security

CrowdStrike Falcon Cloud Security Expands Real-Time CDR to GCP

CrowdStrike enhances Falcon Cloud Security with real-time detection and response for Google Cloud, providing unified visibility and threat protection.

Runtime Rebel Intel
4 min read · Apr 23, 2026
Google Antigravity RCE via Prompt Injection — Mitigation Guide
HIGH
Vulnerabilities

Google Antigravity RCE via Prompt Injection — Mitigation Guide

Google patched a critical RCE flaw in its AI-based Antigravity tool, stemming from a prompt injection vulnerability allowing sandbox escape and arbitrary code execution.

Runtime Rebel Intel
4 min read · Apr 21, 2026
Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure
MEDIUM
Supply Chain

Vercel Breach: Third-Party Context.ai Compromise Leads to Data Exposure

Vercel reports a security incident where a compromised third-party AI tool, Context.ai, allowed attackers to access internal Google Workspace accounts.

Runtime Rebel Intel
4 min read · Apr 20, 2026
Android 17 Privacy Overhaul: Google Blocks 8.3B Malicious Ads
INFO
Threat Intel

Android 17 Privacy Overhaul: Google Blocks 8.3B Malicious Ads

Google announces Android 17 privacy updates and Play policy changes after blocking 8.3 billion ads and 24.9 million fraudulent accounts throughout 2025.

Runtime Rebel Intel
4 min read · Apr 17, 2026
TH
INFO
Threat Intel

Google Deploys Gemini AI to Combat Malvertising and Brand Fraud

Google expands the use of Gemini LLMs to detect sophisticated ad scams, blocking 5.5 billion ads and countering AI-generated brand impersonation tactics.

Runtime Rebel Intel
3 min read · Apr 16, 2026
Big Tech Compliance Failures in CA Privacy Law Opt-Out Requests
MEDIUM
Compliance

Big Tech Compliance Failures in CA Privacy Law Opt-Out Requests

An audit reveals Google, Meta, and Microsoft frequently ignore California privacy law opt-out requests, posing significant compliance and data privacy risks.

Runtime Rebel Intel
4 min read · Apr 15, 2026
Pushpaganda Scam: Detecting AI-Driven Ad Fraud in Google Discover
MEDIUM
Threat Intel

Pushpaganda Scam: Detecting AI-Driven Ad Fraud in Google Discover

Researchers unmask Pushpaganda, a campaign using AI-generated content and SEO poisoning to trick users into enabling malicious browser notifications.

Runtime Rebel Intel
3 min read · Apr 14, 2026
Pixel 10 Modem: Google Implements Rust-Based DNS Parser
INFO
Threat Intel

Pixel 10 Modem: Google Implements Rust-Based DNS Parser

Google integrates Rust-based DNS parsing in Pixel 10 modem firmware to eliminate memory-safety risks and prevent remote code execution at the baseband level.

Runtime Rebel Intel
3 min read · Apr 14, 2026
APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting
HIGH
Threat Intel

APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting

China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.

Runtime Rebel Intel
4 min read · Apr 13, 2026
CL
INFO
Cloud Security

Google Workspace CSE: Securing Gmail on Android and iOS

Google introduces native client-side encryption for Gmail on Android and iOS, enabling enterprise users to control encryption keys on mobile devices.

Runtime Rebel Intel
3 min read · Apr 13, 2026
CL
MEDIUM
Cloud Security

Google Gmail Client-Side Encryption for Android and iOS — Deployment Guide

Google expands Gmail client-side encryption (CSE) to Android and iOS, giving enterprise users full control over encryption keys for mobile email communications.

Runtime Rebel Intel
3 min read · Apr 10, 2026
ID
MEDIUM
Identity & Access

Chrome DBSC: Securing Session Cookies with Device Binding — Analysis

Google introduces Device Bound Session Credentials in Chrome to combat session hijacking by cryptographically linking authentication cookies to local hardware.

Runtime Rebel Intel
4 min read · Apr 10, 2026
Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking
INFO
Identity & Access

Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking

Google releases Device Bound Session Credentials (DBSC) in Chrome 146 for Windows to mitigate cookie theft and session hijacking via hardware-backed security.

Runtime Rebel Intel
4 min read · Apr 10, 2026
VU
HIGH
Vulnerabilities

Exposed Google API Keys in Android Apps Grant Gemini Access

Analysis of Google API keys found in Android apps that enable unauthorized access to Gemini AI endpoints, detailing risks and mitigation for developers.

Runtime Rebel Intel
5 min read · Apr 9, 2026
SU
HIGH
Supply Chain

TeamPCP Supply Chain Campaign: Cisco Source Code Stolen, UNC6780 Activity

Analysis of the TeamPCP supply chain campaign, including the theft of Cisco source code and over 1,000 compromised SaaS environments tracked by Google GTIG as UNC6780.

Runtime Rebel Intel
4 min read · Apr 9, 2026
Claude Mythos Identifies Thousands of Zero-Day Flaws in Major Systems
HIGH
Vulnerabilities

Claude Mythos Identifies Thousands of Zero-Day Flaws in Major Systems

Anthropic's Project Glasswing uses the Claude Mythos AI model to uncover thousands of zero-day vulnerabilities across infrastructure from AWS, Google, and Cisco.

Runtime Rebel Intel
4 min read · Apr 8, 2026