Skip to content
Threat Feed
high advisory

Google Security Updates — July 2026

Roundup of Google security advisories published in July 2026.

CVE search metadata

CVE search record: CVE-2026-15899. Severity: critical. CVSS: 9.6. EPSS: 0.24%. KEV: no. Brief: Google Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-google-security-updates/

CVE search record: CVE-2026-15901. Severity: critical. CVSS: 9.6. EPSS: 0.26%. KEV: no. Brief: Google Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-google-security-updates/

CVE search record: CVE-2026-16423. Severity: high. CVSS: 8.8. EPSS: 0.20%. KEV: no. Brief: Google Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-google-security-updates/

CVE search record: CVE-2026-15904. Severity: high. CVSS: 8.8. EPSS: 0.24%. KEV: no. Brief: Google Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-google-security-updates/

CVE search record: CVE-2026-15902. Severity: high. CVSS: 8.8. EPSS: 0.28%. KEV: no. Brief: Google Security Updates — July 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-07-google-security-updates/

What's new

  • 1. new IOCs Jul 31, 15:31 via cccs
  • 2. OS mac Jul 24, 14:34 via cccs
  • 3. new IOCs Jul 24, 13:24 via anssi
  • 4. added CVE-2026-15902 +1 Jul 23, 10:03 via talos
  • 5. added CVE-2026-16413 +2 Jul 22, 14:52 via anssi

Aggregated Google security advisories for July 2026. CVEs from this cycle are folded into the list below as they are published.

Recommendation

Review affected products and apply Google's July 2026 security updates.

Indicators of compromise

7

domain

4

file_name

3

file_path

1

filename

2

ip

4

other

2

product_name

18

url

TypeValue
urlhttps://www.recordedfuture.com/research/from-castleloader-to-castlerat-tag-150-advances-operations
urlhttps://peter.sh/experiments/chromium-command-line-switches/
urlhttps://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1185/browser_unusual_flag/castle_chrome_shell32.log
file_nameLocal State
file_nameLogin Data
file_path*\temp\*
urlhttps://malpedia.caad.fkie.fraunhofer.de/details/win.redline_stealer
file_path*\AppData\Local\Google\Chrome\User Data\Default\Login Data
urlhttps://x.com/suyog41/status/1825869470323056748
urlhttps://g0njxa.medium.com/from-vietnam-to-united-states-malware-fraud-and-dropshipping-98b7a7b2c36d
domainapps.googleusercontent.com
urlhttps://support.google.com/a/answer/175197
urlhttps://support.google.com/a/answer/7587183
urlhttps://support.google.com/a/answer/7061566
urlhttps://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-google_workspace.html
urlhttps://www.elastic.co/security-labs/google-workspace-attack-surface-part-one
urlhttps://www.elastic.co/security-labs/google-workspace-attack-surface-part-two
urlhttps://sploitus.com/exploit?id=D0DC4908-C0DC-539F-BC8B-A87CCD40BBFF
filenameinvoices.apk
urlhttps://cloudrun01-abc.europe-west3.run.app/
otherkubernetes.io/kube-apiserver-client
othersystem:kube-controller-manager
othersystem:masters
othersystem:admin
ip169.254.169.254
domainmetadata.google.internal
domainenavalenceart[.]com
domainsyncmcchub[.]blogspot[.]com
domainmcc-sync-ads[.]com
urlhttps://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html
urlhttp://172.86.126.18:443/update_ms.msi
ip172.86.126.18
file_nameupdate_ms.msi
file_pathC:\programdata\update_ms.msi
file_namelib.dll
product_namemsaRAT
product_nameChaos ransomware
domaincloudflare.com
domaintwilio.com
urlhttps://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html
urlhttps://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html