Google threat watch

Google product CVE coverage — Chrome, Android, cloud services, and platform component vulnerabilities.

Watch items

Recent Google watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows · sorted newest first

Operations view

mcp toolbox for databases vulnerability (CVE-2026-14541)

HIGH
watchNVDCVE-2026-14541

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a result, the toolbox will accept any valid Google OAuth access token—even those minted for unrelated ecosystem applications—granting unauthorized clients access to protected tools and data backends.

Jul 30, 2026, 10:16 PMOfficial source

mcp toolbox for databases vulnerability (CVE-2026-14539)

MEDIUM
watchNVDCVE-2026-14539

An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted buffer loop (io.ReadAll) without applying defensive constraints such as http.MaxBytesReader or pre-read Content-Length enforcement. By submitting a single, massive HTTP request body, an attacker can linearly consume available host memory until the runtime process is terminated by an Out-Of-Memory (OOM) error.

Jul 30, 2026, 9:16 PMOfficial source

mcp toolbox for databases vulnerability (CVE-2026-14538)

MEDIUM
watchNVDCVE-2026-14538

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset restrictions, but due to a fail-open logic flaw, it bypasses validation when the API returns an empty array for specialized constructs. This allows the attacker to extract structural DDL schemas for explicitly excluded datasets via INFORMATION_SCHEMA, and access downstream federated row data via EXTERNAL_QUERY connections.

Jul 30, 2026, 9:16 PMOfficial source

mcp toolbox for databases vulnerability (CVE-2026-14537)

HIGH
watchNVDCVE-2026-14537

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.

Jul 30, 2026, 9:16 PMOfficial source

chrome vulnerability (CVE-2026-16414)

HIGH
watchNVDCVE-2026-16414

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

Jul 21, 2026, 6:16 PMOfficial source

chrome vulnerability (CVE-2026-14120)

CRITICAL
watchNVDCVE-2026-14120

Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

Jun 30, 2026, 6:17 PMOfficial source

chrome vulnerability (CVE-2026-14109)

CRITICAL
watchNVDCVE-2026-14109

Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

Jun 30, 2026, 6:17 PMOfficial source

chrome vulnerability (CVE-2026-14106)

CRITICAL
watchNVDCVE-2026-14106

Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

Jun 30, 2026, 6:17 PMOfficial source

chrome vulnerability (CVE-2026-14104)

CRITICAL
watchNVDCVE-2026-14104

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

Jun 30, 2026, 6:17 PMOfficial source

chrome vulnerability (CVE-2026-14102)

HIGH
watchNVDCVE-2026-14102

Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

Jun 30, 2026, 6:17 PMOfficial source

chrome vulnerability (CVE-2026-14101)

CRITICAL
watchNVDCVE-2026-14101

Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

Jun 30, 2026, 6:17 PMOfficial source

chrome vulnerability (CVE-2026-14090)

HIGH
watchNVDCVE-2026-14090

Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)

Jun 30, 2026, 6:17 PMOfficial source

chrome vulnerability (CVE-2026-13785)

CRITICAL
watchNVDCVE-2026-13785

Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Jun 30, 2026, 6:16 PMOfficial source

chrome vulnerability (CVE-2026-13784)

HIGH
watchNVDCVE-2026-13784

Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Jun 30, 2026, 6:16 PMOfficial source

chrome vulnerability (CVE-2026-13783)

HIGH
watchNVDCVE-2026-13783

Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Jun 30, 2026, 6:16 PMOfficial source

chrome vulnerability (CVE-2026-13782)

CRITICAL
watchNVDCVE-2026-13782

Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Jun 30, 2026, 6:16 PMOfficial source

chrome vulnerability (CVE-2026-13781)

CRITICAL
watchNVDCVE-2026-13781

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Jun 30, 2026, 6:16 PMOfficial source

chrome vulnerability (CVE-2026-13780)

CRITICAL
watchNVDCVE-2026-13780

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Jun 30, 2026, 6:16 PMOfficial source

chrome vulnerability (CVE-2026-13777)

HIGH
watchNVDCVE-2026-13777

Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Jun 30, 2026, 6:16 PMOfficial source

chrome vulnerability (CVE-2026-13776)

CRITICAL
watchNVDCVE-2026-13776

Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Jun 30, 2026, 6:16 PMOfficial source

Vendor watch hub

What this page covers

The Googlewatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent Google activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

1293

Active

90

Featured

280

Unique CVEs

20

Most recent entry

Jul 30, 2026, 10:16 PM

Feed refreshes daily · 5:15 a.m. Central

Sources·CISA KEV and NVD (product vendor coverage)

"Most recent entry" is the newest item the upstream feed has published — not our sync time.

Related vendors

Other productivity vendors in the radar

Vendor watch FAQ

Common questions

What is the Google threat watch page?

It is the Google-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the Google watch page?

Use it to confirm whether current Google issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to Google security issues?

Yes. ITECS can help map Google advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.