Google Chrome vulnerabilities
5,463 known vulnerabilities affecting google/chrome.
Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65
Vulnerabilities
Page 1 of 274
CVE-2014-0497P1CRITICALCVSS 9.8KEVPoCfixed in 32.0.1700.1072014-02-05
CVE-2014-0497 [CRITICAL] CWE-191 CVE-2014-0497: Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2023-4863P1HIGHCVSS 8.8KEVPoCfixed in 116.0.5845.1872023-09-12
CVE-2023-4863 [HIGH] CWE-787 CVE-2023-4863: Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2011-0611P1HIGHCVSS 8.8KEVPoCfixed in 10.0.648.2052011-04-13
CVE-2011-0611 [HIGH] CWE-843 CVE-2011-0611: Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and e
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.
nvd
CVE-2020-6418P1HIGHCVSS 8.8KEVPoCfixed in 80.0.3987.122≥ unspecified, < 80.0.3987.1222020-02-27
CVE-2020-6418 [HIGH] CWE-843 CVE-2020-6418: Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentiall
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-17463P1HIGHCVSS 8.8KEVPoCfixed in 70.0.3538.67≥ unspecified, < 70.0.3538.642018-11-14
CVE-2018-17463 [HIGH] CVE-2018-17463: Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attac
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2021-21220P1HIGHCVSS 8.8KEVPoCfixed in 89.0.4389.128≥ unspecified, < 89.0.4389.1282021-04-26
CVE-2021-21220 [HIGH] CWE-787 CVE-2021-21220: Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a r
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30632P1HIGHCVSS 8.8KEVPoCfixed in 93.0.4577.82≥ unspecified, < 93.0.4577.822021-10-08
CVE-2021-30632 [HIGH] CWE-787 CVE-2021-30632: Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potent
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30551P1HIGHCVSS 8.8KEVPoCfixed in 91.0.4472.101≥ unspecified, < 91.0.4472.1012021-06-15
CVE-2021-30551 [HIGH] CWE-843 CVE-2021-30551: Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentiall
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-5217P1HIGHCVSS 8.8KEVPoCfixed in 117.0.5938.132≥ 117.0.5938.132, < 117.0.5938.1322023-09-28
CVE-2023-5217 [HIGH] CWE-787 CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-15999P1CRITICALCVSS 9.6KEVPoCfixed in 86.0.4240.111≥ unspecified, < 86.0.4240.1112020-11-03
CVE-2020-15999 [CRITICAL] CWE-787 CVE-2020-15999: Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker t
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6065P1HIGHCVSS 8.8KEVPoCfixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6065 [HIGH] CWE-190 CVE-2018-6065: Integer overflow in computing the required allocation size when instantiating a new javascript objec
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13720P1HIGHCVSS 8.8KEVPoCfixed in 78.0.3904.87≥ unspecified, < 78.0.3904.872019-11-25
CVE-2019-13720 [HIGH] CWE-416 CVE-2019-13720: Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to poten
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2011-0609P1HIGHCVSS 7.8KEVPoCfixed in 10.0.648.1342011-03-15
CVE-2011-0609 [HIGH] CVE-2011-0609: Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux,
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary co
nvd
CVE-2021-21224P1HIGHCVSS 8.8KEVPoCfixed in 90.0.4430.85≥ unspecified, < 90.0.4430.852021-04-26
CVE-2021-21224 [HIGH] CWE-843 CVE-2021-21224: Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arb
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2023-2033P1HIGHCVSS 8.8KEVPoCfixed in 112.0.5615.121≥ 112.0.5615.121, < 112.0.5615.1212023-04-14
CVE-2023-2033 [HIGH] CWE-843 CVE-2023-2033: Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potential
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-2441P1HIGHCVSS 8.8KEVPoCfixed in 145.0.7632.75fixed in 145.0.7632.76+1 more2026-02-13
CVE-2026-2441 [HIGH] CWE-416 CVE-2026-2441: Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute a
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-14174P1HIGHCVSS 8.8KEVPoC≥ 143.0.7499.41, < 143.0.7499.110≥ 143.0.7499.40, < 143.0.7499.109+1 more2025-12-12
CVE-2025-14174 [HIGH] CWE-787 CVE-2025-14174: Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remot
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3079P1HIGHCVSS 8.8KEVPoCfixed in 114.0.5735.110≥ 114.0.5735.110, < 114.0.5735.1102023-06-05
CVE-2023-3079 [HIGH] CWE-843 CVE-2023-3079: Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potential
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-7971P1CRITICALCVSS 9.6KEVPoCfixed in 128.0.6613.84≥ 128.0.6613.84, < 128.0.6613.842024-08-21
CVE-2024-7971 [CRITICAL] CWE-843 CVE-2024-7971: Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit he
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-38003P1HIGHCVSS 8.8KEVPoCfixed in 95.0.4638.69≥ unspecified, < 95.0.4638.692021-11-23
CVE-2021-38003 [HIGH] CWE-755 CVE-2021-38003: Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
1 / 274Next →