cbcvebase.

Google Chrome vulnerabilities

5,463 known vulnerabilities affecting google/chrome.

Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65

Vulnerabilities

Page 10 of 274
CVE-2024-1670P3HIGHCVSS 8.8fixed in 122.0.6261.57≥ 122.0.6261.57, < 122.0.6261.572024-02-21
CVE-2024-1670 [HIGH] CWE-416 CVE-2024-1670: Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentia Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-4058P3HIGHCVSS 8.8fixed in 124.0.6367.78≥ 124.0.6367.78, < 124.0.6367.782024-05-01
CVE-2024-4058 [HIGH] CWE-843 CVE-2024-4058: Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potenti Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-3062P3CRITICALCVSS 9.8fixed in 145.0.7632.116fixed in 145.0.7632.117+1 more2026-02-23
CVE-2026-3062 [CRITICAL] CWE-125 CVE-2026-3062: Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remot Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-14765P3HIGHCVSS 8.8fixed in 143.0.7499.146≥ 143.0.7499.147, < 143.0.7499.1472025-12-16
CVE-2025-14765 [HIGH] CWE-416 CVE-2025-14765: Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to poten Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11651P3CRITICALCVSS 9.6fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11651 [CRITICAL] CWE-416 CVE-2026-11651: Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to exec Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14405P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14405 [CRITICAL] CWE-457 CVE-2026-14405: Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-2135P3HIGHCVSS 8.8fixed in 134.0.6998.88≥ 134.0.6998.88, < 134.0.6998.882025-03-10
CVE-2025-2135 [HIGH] CWE-843 CVE-2025-2135: Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentiall Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-30558P3HIGHCVSS 8.8fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772023-01-02
CVE-2021-30558 [HIGH] CVE-2021-30558: Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 al Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chrome security severity: Medium)
nvd
CVE-2024-1675P3HIGHCVSS 8.8fixed in 122.0.6261.57≥ 122.0.6261.57, < 122.0.6261.572024-02-21
CVE-2024-1675 [HIGH] CWE-284 CVE-2024-1675: Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-14766P3HIGHCVSS 8.8fixed in 143.0.7499.146≥ 143.0.7499.147, < 143.0.7499.1472025-12-16
CVE-2025-14766 [HIGH] CWE-125 CVE-2025-14766: Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacke Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13776P3CRITICALCVSS 9.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13776 [CRITICAL] CWE-843 CVE-2026-13776: Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had com Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-0906P3CRITICALCVSS 9.8fixed in 144.0.7559.59fixed in 144.0.7559.60+1 more2026-01-20
CVE-2026-0906 [CRITICAL] CWE-451 CVE-2026-0906: Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4430P3HIGHCVSS 8.8fixed in 116.0.5845.110≥ 116.0.5845.110, < 116.0.5845.1102023-08-23
CVE-2023-4430 [HIGH] CWE-416 CVE-2023-4430: Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to poten Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-7656P3HIGHCVSS 8.8fixed in 138.0.7204.157≥ 138.0.7204.157, < 138.0.7204.1572025-07-15
CVE-2025-7656 [HIGH] CWE-472 CVE-2025-7656: Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potenti Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-21121P3CRITICALCVSS 9.6fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21121 [CRITICAL] CWE-416 CVE-2021-21121: Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2018-20346P3HIGHCVSS 8.1fixed in 71.0.3578.802018-12-21
CVE-2018-20346 [HIGH] CWE-190 CVE-2018-20346: SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and result SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magell
nvd
CVE-2023-5482P3HIGHCVSS 8.8fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5482 [HIGH] CWE-345 CVE-2023-5482: Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attack Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2017-15398P3CRITICALCVSS 9.8fixed in 62.0.3202.892018-08-28
CVE-2017-15398 [CRITICAL] CWE-119 CVE-2017-15398: A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to gain code execution via a malicious server.
nvd
CVE-2024-9954P3HIGHCVSS 8.8fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9954 [HIGH] CWE-416 CVE-2024-9954: Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentiall Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-12692P3HIGHCVSS 8.8fixed in 131.0.6778.204≥ 131.0.6778.204, < 131.0.6778.2042024-12-18
CVE-2024-12692 [HIGH] CWE-843 CVE-2024-12692: Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potential Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase