cbcvebase.

Google Chrome vulnerabilities

5,463 known vulnerabilities affecting google/chrome.

Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65

Vulnerabilities

Page 11 of 274
CVE-2021-30625P3HIGHCVSS 8.8fixed in 93.0.4577.82≥ unspecified, < 93.0.4577.822021-10-08
CVE-2021-30625 [HIGH] CWE-416 CVE-2021-30625: Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2025-9478P3HIGHCVSS 8.8fixed in 139.0.7258.154≥ 139.0.7258.154, < 139.0.7258.1542025-08-26
CVE-2025-9478 [HIGH] CWE-416 CVE-2025-9478: Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potent Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2025-4052P3CRITICALCVSS 9.8fixed in 136.0.7103.59≥ 136.0.7103.59, < 136.0.7103.592025-05-05
CVE-2025-4052 [CRITICAL] CWE-838 CVE-2025-4052: Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote at Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-9132P3HIGHCVSS 8.8fixed in 139.0.7258.138≥ 139.0.7258.138, < 139.0.7258.1382025-08-20
CVE-2025-9132 [HIGH] CWE-787 CVE-2025-9132: Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to pote Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2011-3026P3MEDIUMCVSS 6.8fixed in 17.0.963.562012-02-16
CVE-2011-3026 [MEDIUM] CWE-190 CVE-2011-3026: Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.
nvd
CVE-2021-30598P3HIGHCVSS 8.8fixed in 92.0.4515.159≥ unspecified, < 92.0.4515.1592021-08-26
CVE-2021-30598 [HIGH] CWE-843 CVE-2021-30598: Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute ar Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2017-5116P3HIGHCVSS 8.8fixed in 61.0.3163.79fixed in 61.0.3163.812017-10-27
CVE-2017-5116 [HIGH] CWE-843 CVE-2017-5116: Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.31 Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2026-16806P3HIGHCVSS 8.8fixed in 150.0.7871.186≥ 150.0.7871.186, < 150.0.7871.1862026-07-23
CVE-2026-16806 [HIGH] CWE-416 CVE-2026-16806: Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execu Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-16420P3HIGHCVSS 8.8fixed in 150.0.7871.182≥ 150.0.7871.182, < 150.0.7871.1822026-07-21
CVE-2026-16420 [HIGH] CWE-843 CVE-2026-16420: Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to exe Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-16805P3HIGHCVSS 8.8fixed in 150.0.7871.186≥ 150.0.7871.186, < 150.0.7871.1862026-07-23
CVE-2026-16805 [HIGH] CWE-416 CVE-2026-16805: Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execut Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-0434P3HIGHCVSS 8.8fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0434 [HIGH] CWE-122 CVE-2025-0434: Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-9122P3HIGHCVSS 8.8fixed in 129.0.6668.70≥ 129.0.6668.70, < 129.0.6668.702024-09-25
CVE-2024-9122 [HIGH] CWE-843 CVE-2024-9122: Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform ou Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-30557P3HIGHCVSS 8.8fixed in 91.0.4472.114≥ unspecified, < 91.0.4472.1142021-07-02
CVE-2021-30557 [HIGH] CWE-416 CVE-2021-30557: Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convince Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2024-2887P3HIGHCVSS 7.7fixed in 123.0.6312.86≥ 123.0.6312.86, < 123.0.6312.862024-03-26
CVE-2024-2887 [HIGH] CWE-843 CVE-2024-2887: Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to e Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5841P3HIGHCVSS 8.8fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5841 [HIGH] CWE-416 CVE-2024-5841: Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentiall Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-12382P3HIGHCVSS 8.8fixed in 131.0.6778.139≥ 131.0.6778.139, < 131.0.6778.1392024-12-12
CVE-2024-12382 [HIGH] CWE-416 CVE-2024-12382: Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to po Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-12381P3HIGHCVSS 8.8fixed in 131.0.6778.139≥ 131.0.6778.139, < 131.0.6778.1392024-12-12
CVE-2024-12381 [HIGH] CWE-843 CVE-2024-12381: Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potential Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-21124P3CRITICALCVSS 9.6fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21124 [CRITICAL] CWE-416 CVE-2021-21124: Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 all Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2025-5063P3HIGHCVSS 8.8fixed in 137.0.7151.55≥ 137.0.7151.55, < 137.0.7151.552025-05-27
CVE-2025-5063 [HIGH] CWE-416 CVE-2025-5063: Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to p Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2018-6056P3HIGHCVSS 8.8fixed in 64.0.3282.168≥ unspecified, < 64.0.3282.1682019-01-09
CVE-2018-6056 [HIGH] CWE-704 CVE-2018-6056: Type confusion could lead to a heap out-of-bounds write in V8 in Google Chrome prior to 64.0.3282.16 Type confusion could lead to a heap out-of-bounds write in V8 in Google Chrome prior to 64.0.3282.168 allowing a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase