"CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild."
This line, I think? >This CVE is in CISA's Known Exploited Vulnerabilities Catalog
"Google has confirmed that an exploit exists in the wild but has not disclosed information about the threat actors, targeted organizations, or attack campaigns while the update is still rolling out."