Google Chrome vulnerabilities

3,975 known vulnerabilities affecting google/chrome.

Total CVEs
3,975
CISA KEV
74
actively exploited
Public exploits
63
Exploited in wild
65
Severity breakdown
CRITICAL297HIGH2024MEDIUM1626LOW17UNKNOWN11

Vulnerabilities

Page 108 of 199
CVE-2018-17460MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-17460 [MEDIUM] CWE-20 CVE-2018-17460: Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a rem Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2019-5830MEDIUMCVSS 6.5fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5830 [MEDIUM] CVE-2019-5830: Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote atta Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5805MEDIUMCVSS 6.5fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5805 [MEDIUM] CWE-416 CVE-2019-5805: Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potent Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2019-5832MEDIUMCVSS 6.5fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5832 [MEDIUM] CVE-2019-5832: Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a r Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5786MEDIUMCVSS 6.5KEVPoCfixed in 72.0.3626.121≥ unspecified, < 72.0.3626.1212019-06-27
CVE-2019-5786 [MEDIUM] CWE-416 CVE-2019-5786: Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2018-6177MEDIUMCVSS 4.3fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-6177 [MEDIUM] CWE-200 CVE-2018-6177: Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5812MEDIUMCVSS 6.5fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5812 [MEDIUM] CVE-2019-5812: Inadequate security UI in iOS UI in Google Chrome prior to 74.0.3729.108 allowed a remote attacker t Inadequate security UI in iOS UI in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2018-16069MEDIUMCVSS 6.5fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-06-27
CVE-2018-16069 [MEDIUM] CWE-125 CVE-2018-16069: Unintended floating-point error accumulation in SwiftShader in Google Chrome prior to 69.0.3497.81 a Unintended floating-point error accumulation in SwiftShader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5823MEDIUMCVSS 5.4fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5823 [MEDIUM] CWE-601 CVE-2019-5823: Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2017-5028MEDIUMCVSS 6.5fixed in 56.0.2924.76≥ unspecified, < 56.0.2924.762019-06-27
CVE-2017-5028 [MEDIUM] CWE-20 CVE-2017-5028: Insufficient data validation in V8 in Google Chrome prior to 56.0.2924.76 allowed a remote attacker Insufficient data validation in V8 in Google Chrome prior to 56.0.2924.76 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6150MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-06-27
CVE-2018-6150 [MEDIUM] CWE-200 CVE-2018-6150: Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-16064MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-16064 [MEDIUM] CWE-20 CVE-2018-16064: Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an att Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2019-5818MEDIUMCVSS 6.5fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5818 [MEDIUM] CWE-908 CVE-2019-5818: Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obt Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.
nvd
CVE-2018-6159MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-6159 [MEDIUM] CWE-200 CVE-2018-6159: Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 68.0.3440.75 allowed a re Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2018-6128MEDIUMCVSS 6.1fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-06-27
CVE-2018-6128 [MEDIUM] CWE-79 CVE-2018-6128: Incorrect URL parsing in WebKit in Google Chrome on iOS prior to 67.0.3396.62 allowed a remote attac Incorrect URL parsing in WebKit in Google Chrome on iOS prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2019-5839MEDIUMCVSS 4.3fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5839 [MEDIUM] CWE-20 CVE-2019-5839: Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote atta Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.
nvd
CVE-2018-6136MEDIUMCVSS 6.5fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-06-27
CVE-2018-6136 [MEDIUM] CWE-125 CVE-2018-6136: Missing type check in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform Missing type check in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2018-6129MEDIUMCVSS 6.5PoCfixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-06-27
CVE-2018-6129 [MEDIUM] CWE-125 CVE-2018-6129: Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacke Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2018-16075MEDIUMCVSS 5.3fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-06-27
CVE-2018-16075 [MEDIUM] CVE-2018-16075: Insufficient file type enforcement in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote Insufficient file type enforcement in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain local file data via a crafted HTML page.
nvd
CVE-2019-5785MEDIUMCVSS 6.5fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-06-27
CVE-2019-5785 [MEDIUM] CWE-787 CVE-2019-5785: Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote att Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
nvd