cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL496HIGH2798MEDIUM2448LOW79UNKNOWN10

Vulnerabilities

Page 108 of 292
CVE-2018-6152P3CRITICALCVSS 9.6fixed in 66.0.3359.106≥ unspecified, < 66.0.3359.1172018-12-04
CVE-2018-6152 [CRITICAL] CWE-434 CVE-2018-6152: The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as s The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page and user interaction.
nvd
CVE-2015-1290P3HIGHCVSS 8.8fixed in 44.0.2403.892018-01-09
CVE-2015-1290 [HIGH] CWE-119 CVE-2015-1290: The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted web site.
nvd
CVE-2020-6469P3CRITICALCVSS 9.6fixed in 83.0.4103.61≥ unspecified, < 83.0.4103.612020-05-21
CVE-2020-6469 [CRITICAL] CWE-276 CVE-2020-6469: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2026-13891P3HIGHCVSS 7.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13891 [HIGH] CWE-20 CVE-2026-13891: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 all Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13824P3HIGHCVSS 7.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13824 [HIGH] CWE-20 CVE-2026-13824: Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remo Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13856P3HIGHCVSS 7.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13856 [HIGH] CWE-20 CVE-2026-13856: Insufficient validation of untrusted input in Speech in Google Chrome on Android prior to 150.0.7871 Insufficient validation of untrusted input in Speech in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10900P3HIGHCVSS 7.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10900 [HIGH] CWE-416 CVE-2026-10900: Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10899P3HIGHCVSS 7.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10899 [HIGH] CWE-416 CVE-2026-10899: Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker w Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10969P3HIGHCVSS 7.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10969 [HIGH] CWE-20 CVE-2026-10969: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 all Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9117P3HIGHCVSS 7.5fixed in 148.0.7778.179≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9117 [HIGH] CWE-843 CVE-2026-9117: Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote a Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High)
nvd
CVE-2026-15777P3HIGHCVSS 7.5fixed in 150.0.7871.125≥ 150.0.7871.125, < 150.0.7871.1252026-07-14
CVE-2026-15777 [HIGH] CWE-416 CVE-2026-15777: Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7357P3HIGHCVSS 7.5fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7357 [HIGH] CWE-416 CVE-2026-7357: Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had com Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11636P3HIGHCVSS 7.5fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11636 [HIGH] CWE-416 CVE-2026-11636: Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote atta Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-9954P3HIGHCVSS 7.5fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9954 [HIGH] CWE-416 CVE-2026-9954: Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who co Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-2319P3HIGHCVSS 7.5fixed in 145.0.7632.45≥ 145.0.7632.45, < 145.0.7632.452026-02-11
CVE-2026-2319 [HIGH] CWE-362 CVE-2026-2319: Race in DevTools in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a u Race in DevTools in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures and install a malicious extension to potentially exploit object corruption via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-11265P3HIGHCVSS 7.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11265 [HIGH] CWE-352 CVE-2026-11265: Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-13029P3HIGHCVSS 7.5fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13029 [HIGH] CWE-416 CVE-2026-13029: Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker wh Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2026-17916P3HIGHCVSS 7.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17916 [HIGH] CWE-346 CVE-2026-17916: Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-16422P3HIGHCVSS 7.5fixed in 150.0.7871.182≥ 150.0.7871.182, < 150.0.7871.1822026-07-21
CVE-2026-16422 [HIGH] CWE-20 CVE-2026-16422: Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7 Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)
nvd
CVE-2017-15402P3CRITICALCVSS 9.6fixed in 62.0.3202.74≥ unspecified, < 62.0.3202.742019-01-09
CVE-2017-15402 [CRITICAL] CWE-20 CVE-2017-15402: Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same process in Navigation in Google Chrome on Chrome OS prior to 62.0.3202.74 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase