Google Security Research
1,215 exploits
Active since May 2013
Apple iOS <9.3 - Privilege Escalation
CVSS 7.8
Apple Mac OSX 10.10 - IOKit IntelAccelerator Null Pointer Dereference
Apple iOS <9.2, macOS <10.11.2, tvOS <9.1, watchOS <2.1 - Memory Corruption in Kernel
Apple iOS <9.1, macOS <10.11.1, watchOS <2.0.1 - Remote Code Execution via IOAcceleratorFamily Memory Corruption
watchOS < 2.1 - Local Privilege Escalation via Crafted Mach Message
Apple <10.2.1, <10.0.3, <10.1.1 - SSRF
CVSS 6.5
Google Chrome 72.0.3626.121 / 74.0.3725.0 - 'NewFixedDoubleArray' Integer Overflow
Google Chrome 72.0.3626.96 / 74.0.3702.0 - 'JSPromise::TriggerPromiseReactions' Type Confusion
Google Chrome <65.0.3325.146 - Heap Corruption
CVSS 8.8
Samba < 4.4.12 - Symlink Race Condition
CVSS 7.5
Transmission < 2.92 - Unauthenticated Remote Code Execution via DNS Rebinding
CVSS 8.8
μTorrent (uTorrent) Classic/Web - JSON-RPC Remote Code Execution / Information Disclosure
Apple Safari 10.0.3(12602.4.8) / WebKit - 'HTMLObjectElement::updateWidget' Universal Cross-Site Scripting
Safari < 10.1 - Same Origin Policy Bypass via WebKit JavaScript Bindings
CVSS 6.5
Safari < 10.1 - Same Origin Policy Bypass via WebKit
CVSS 6.5
Apple WebKit / Safari 10.0.2(12602.3.12.0.1) - 'operationSpreadGeneric' Universal Cross-Site Scripting
Apple WebKit / Safari 10.0.2(12602.3.12.0.1) - 'PrototypeMap::createEmptyStructure' Universal Cross-Site Scripting
iCloud < 6.2 - Exposure of Sensitive Information via WebKit Same Origin Policy Bypass
CVSS 6.5
Safari < 10.1 - Same Origin Policy Bypass via WebKit
CVSS 6.5
Safari < 10.1.1 - Universal Cross-Site Scripting via WebKit Editor Commands
CVSS 6.1
Safari < 10.1 - Universal Cross-Site Scripting via Crafted Frame Objects
CVSS 6.1
Safari < 10.1 - Remote Code Execution via WebKit Memory Corruption
CVSS 8.8
iPhone OS < 10.2.1 - Remote Popup Launch via WebKit
CVSS 6.5
iPhone OS < 10.2.1 and Safari < 10.0.3 - Same Origin Policy Bypass in WebKit
CVSS 6.5
Wireshark 1.12.x < 1.12.9 and 2.0.x < 2.0.1 - Denial of Service via RSVP Dissector Use-After-Free
CVSS 5.5