Google: Five Vulnerabilities in Chrome and Cloud Integration Disclosed Together
Key findings • Five vulnerabilities disclosed by Google on September 28, 2026, affecting Chrome and Cloud Application Integration. • Two critical vulnerabilities in Google Cloud Application I…

Key findings
- Five vulnerabilities disclosed by Google on September 28, 2026, affecting Chrome and Cloud Application Integration.
- Two critical vulnerabilities in Google Cloud Application Integration allow for arbitrary code execution and internal RPC execution.
- A high-severity flaw in Google Cloud Application Integration enables exfiltration of internal files.
- Google Chrome's Codecs component has a medium-severity vulnerability related to out-of-bounds memory access.
- A medium-severity vulnerability in fuse-archive allows for arbitrary local code execution via PATH manipulation.
On September 28, 2026, Google disclosed a batch of five vulnerabilities affecting its products, including Google Chrome and Google Cloud Application Integration. The vulnerabilities, disclosed within a 14-hour window, range in severity from Medium to Critical, highlighting potential risks for users of these services.
Two critical vulnerabilities were identified in Google Cloud Application Integration. CVE-2026-81867, a Deserialization of Untrusted Data flaw, could allow an authenticated user to execute arbitrary code on production servers. CVE-2026-19759, an Incorrect Authorization vulnerability, enables an authenticated user to execute internal RPCs with privileged identities. These issues were patched in versions prior to June 28, 2026, and June 17, 2026, respectively.
Another significant vulnerability, CVE-2026-81375 (High severity), also affects Google Cloud Application Integration. This Confused Deputy vulnerability allows an authenticated attacker to exfiltrate arbitrary Google-internal files by providing a crafted attachment file path. This was addressed in versions prior to June 30, 2026.
In Google Chrome, CVE-2026-13018 (Medium severity) was disclosed, stemming from insufficient validation of untrusted input in Codecs. This could permit a remote attacker to perform out-of-bounds memory access using a specially crafted video file. The vulnerability affects versions prior to 147.0.7727.55.
Lastly, CVE-2026-87723 (Medium severity) impacts Google fuse-archive versions prior to 1.24. An attacker could exploit this by manipulating the system's PATH environment variable to prepend a directory containing a malicious binary, leading to arbitrary local code execution under the user's security context.
These vulnerabilities underscore the importance of timely patching and security updates for Google products. Users are advised to ensure their systems are updated to the latest versions to mitigate these risks. The coordinated disclosure of these CVEs on a single day indicates a focused effort by Google to address and communicate security issues to its user base.