Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10
Vulnerabilities
Page 105 of 292
CVE-2022-3055P3HIGHCVSS 8.8fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3055 [HIGH] CWE-416 CVE-2022-3055: Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who co
Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2399P3HIGHCVSS 8.8fixed in 100.0.4896.88≥ unspecified, < 100.0.4896.882022-07-28
CVE-2022-2399 [HIGH] CWE-416 CVE-2022-2399: Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potent
Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-3051P3HIGHCVSS 8.8fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3051 [HIGH] CWE-787 CVE-2022-3051: Heap buffer overflow in Exosphere in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allow
Heap buffer overflow in Exosphere in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.
nvd
CVE-2022-2854P3HIGHCVSS 8.8fixed in 104.0.5112.101≥ unspecified, < 104.0.5112.1012022-09-26
CVE-2022-2854 [HIGH] CWE-362 CVE-2022-2854: Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to
Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2857P3HIGHCVSS 8.8fixed in 104.0.5112.101≥ unspecified, < 104.0.5112.1012022-09-26
CVE-2022-2857 [HIGH] CWE-362 CVE-2022-2857: Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potent
Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-3058P3HIGHCVSS 8.8fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3058 [HIGH] CWE-416 CVE-2022-3058: Use after free in Sign-In Flow in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who
Use after free in Sign-In Flow in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.
nvd
CVE-2022-2603P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2603 [HIGH] CWE-416 CVE-2022-2603: Use after free in Omnibox in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to poten
Use after free in Omnibox in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-4190P3HIGHCVSS 8.8fixed in 108.0.5359.71≥ unspecified, < 108.0.5359.712022-11-30
CVE-2022-4190 [HIGH] CVE-2022-4190: Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote a
Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-3422P3HIGHCVSS 8.8fixed in 114.0.5735.198≥ 114.0.5735.198, < 114.0.5735.1982023-06-26
CVE-2023-3422 [HIGH] CWE-416 CVE-2023-3422: Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convin
Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3448P3HIGHCVSS 8.8fixed in 106.0.5249.119≥ unspecified, < 106.0.5249.1192022-11-09
CVE-2022-3448 [HIGH] CWE-416 CVE-2022-3448: Use after free in Permissions API in Google Chrome prior to 106.0.5249.119 allowed a remote attacker
Use after free in Permissions API in Google Chrome prior to 106.0.5249.119 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4366P3HIGHCVSS 8.8fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4366 [HIGH] CWE-416 CVE-2023-4366: Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinc
Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-2614P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2614 [HIGH] CWE-416 CVE-2022-2614: Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to
Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2604P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2604 [HIGH] CWE-416 CVE-2022-2604: Use after free in Safe Browsing in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to
Use after free in Safe Browsing in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2623P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2623 [HIGH] CWE-362 CVE-2022-2623: Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attack
Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2023-0933P3HIGHCVSS 8.8fixed in 110.0.5481.177≥ 110.0.5481.177, < 110.0.5481.1772023-02-22
CVE-2023-0933 [HIGH] CWE-190 CVE-2023-0933: Integer overflow in PDF in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potent
Integer overflow in PDF in Google Chrome prior to 110.0.5481.177 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)
nvd
CVE-2023-0927P3HIGHCVSS 8.8fixed in 110.0.5481.177≥ 110.0.5481.177, < 110.0.5481.1772023-02-22
CVE-2023-0927 [HIGH] CWE-416 CVE-2023-0927: Use after free in Web Payments API in Google Chrome on Android prior to 110.0.5481.177 allowed a rem
Use after free in Web Payments API in Google Chrome on Android prior to 110.0.5481.177 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3049P3HIGHCVSS 8.8fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3049 [HIGH] CWE-362 CVE-2022-3049: Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a
Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-1216P3HIGHCVSS 8.8fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1216 [HIGH] CWE-416 CVE-2023-1216: Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had
Use after free in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had convienced the user to engage in direct UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-2458P3HIGHCVSS 8.8fixed in 113.0.5672.114≥ 113.0.5672.114, < 113.0.5672.1142023-05-12
CVE-2023-2458 [HIGH] CWE-416 CVE-2023-2458: Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a rem
Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: High)
nvd
CVE-2022-3042P3HIGHCVSS 8.8fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3042 [HIGH] CWE-362 CVE-2022-3042: Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote att
Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd