Google Chrome vulnerabilities

3,975 known vulnerabilities affecting google/chrome.

Total CVEs
3,975
CISA KEV
74
actively exploited
Public exploits
61
Exploited in wild
65
Severity breakdown
CRITICAL297HIGH2029MEDIUM1630LOW17UNKNOWN2

Vulnerabilities

Page 1 of 199
CVE-2026-6296CRITICALCVSS 9.6≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6296 [CRITICAL] CWE-122 CVE-2026-6296: Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
cvelistv5nvd
CVE-2026-6317HIGHCVSS 8.8≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6317 [HIGH] CWE-416 CVE-2026-6317: Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6303HIGHCVSS 8.8≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6303 CWE-416 CVE-2026-6303: Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execu Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6318HIGHCVSS 8.8≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6318 CWE-416 CVE-2026-6318: Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execu Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-6299HIGHCVSS 8.8≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6299 [HIGH] CWE-416 CVE-2026-6299: Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to ex Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
cvelistv5nvd
CVE-2026-6309HIGHCVSS 8.3≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6309 [HIGH] CWE-416 CVE-2026-6309: Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had com Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6314HIGHCVSS 8.3≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6314 [HIGH] CWE-787 CVE-2026-6314: Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who ha Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6359HIGHCVSS 8.8≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6359 [HIGH] CWE-416 CVE-2026-6359: Use after free in Video in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacke Use after free in Video in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6305HIGHCVSS 8.8≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6305 [HIGH] CWE-122 CVE-2026-6305: Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6308HIGHCVSS 7.5≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6308 CWE-125 CVE-2026-6308: Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who c Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6358HIGHCVSS 8.8≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6358 [HIGH] CWE-416 CVE-2026-6358: Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker t Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Critical)
cvelistv5nvd
CVE-2026-6315HIGHCVSS 8.8≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6315 [HIGH] CWE-416 CVE-2026-6315: Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote a Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6316HIGHCVSS 8.8≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6316 [HIGH] CWE-416 CVE-2026-6316: Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execut Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6311HIGHCVSS 8.3≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6311 [HIGH] CWE-457 CVE-2026-6311: Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a rem Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6297HIGHCVSS 8.3≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6297 [HIGH] CWE-416 CVE-2026-6297: Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
cvelistv5nvd
CVE-2026-6307HIGHCVSS 8.8≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6307 [HIGH] CWE-843 CVE-2026-6307: Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to exe Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6302HIGHCVSS 8.8≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6302 [HIGH] CWE-416 CVE-2026-6302: Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execut Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6361HIGHCVSS 7.2≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6361 [HIGH] CWE-122 CVE-2026-6361: Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
cvelistv5nvd
CVE-2026-6319HIGHCVSS 7.5≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6319 CWE-416 CVE-2026-6319: Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote atta Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-6301HIGHCVSS 8.8≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6301 [HIGH] CWE-843 CVE-2026-6301: Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to exe Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
cvelistv5nvd
1 / 199Next →
Google Chrome vulnerabilities | cvebase