cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 114 of 292
CVE-2020-15998P3HIGHCVSS 8.8fixed in 86.0.4240.99≥ unspecified, < 86.0.4240.992020-11-03
CVE-2020-15998 [HIGH] CWE-416 CVE-2020-15998: Use after free in USB in Google Chrome prior to 86.0.4240.99 allowed a remote attacker who had compr Use after free in USB in Google Chrome prior to 86.0.4240.99 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2022-0465P3HIGHCVSS 8.8fixed in 98.0.4758.80≥ unspecified, < 98.0.4758.802022-04-05
CVE-2022-0465 [HIGH] CWE-416 CVE-2022-0465: Use after free in Extensions in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to pot Use after free in Extensions in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via user interaction.
nvd
CVE-2022-0469P3HIGHCVSS 8.8fixed in 98.0.4758.80≥ unspecified, < 98.0.4758.802022-04-05
CVE-2022-0469 [HIGH] CWE-416 CVE-2022-0469: Use after free in Cast in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convince Use after free in Cast in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific interactions to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0468P3HIGHCVSS 8.8fixed in 98.0.4758.80≥ unspecified, < 98.0.4758.802022-04-05
CVE-2022-0468 [HIGH] CWE-416 CVE-2022-0468: Use after free in Payments in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to poten Use after free in Payments in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-1144P3HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1144 [HIGH] CWE-416 CVE-2022-1144: Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convin Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
nvd
CVE-2022-0463P3HIGHCVSS 8.8fixed in 98.0.4758.80≥ unspecified, < 98.0.4758.802022-04-05
CVE-2022-0463 [HIGH] CWE-416 CVE-2022-0463: Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.
nvd
CVE-2023-2726P3HIGHCVSS 8.8fixed in 113.0.5672.126≥ 113.0.5672.126, < 113.0.5672.1262023-05-16
CVE-2023-2726 [HIGH] CVE-2023-2726: Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-0698P3HIGHCVSS 8.8fixed in 110.0.5481.77≥ unspecified, < 110.0.5481.772023-02-07
CVE-2023-0698 [HIGH] CWE-125 CVE-2023-0698: Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to pe Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-1136P3HIGHCVSS 8.8fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1136 [HIGH] CWE-416 CVE-2022-1136: Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an attacker who convince Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific set of user gestures.
nvd
CVE-2021-38015P3HIGHCVSS 8.8fixed in 96.0.4664.45≥ unspecified, < 96.0.4664.452021-12-23
CVE-2021-38015 [HIGH] CWE-20 CVE-2021-38015: Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2022-0605P3HIGHCVSS 8.8fixed in 98.0.4758.102≥ unspecified, < 98.0.4758.1022022-04-05
CVE-2022-0605 [HIGH] CWE-416 CVE-2022-0605: Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convi Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-4191P3HIGHCVSS 8.8fixed in 108.0.5359.71≥ unspecified, < 108.0.5359.712022-11-30
CVE-2022-4191 [HIGH] CWE-416 CVE-2022-4191: Use after free in Sign-In in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who conv Use after free in Sign-In in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via profile destruction. (Chromium security severity: Medium)
nvd
CVE-2022-2621P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2621 [HIGH] CWE-416 CVE-2022-2621: Use after free in Extensions in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinc Use after free in Extensions in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2022-0302P3HIGHCVSS 8.8fixed in 97.0.4692.99≥ unspecified, < 97.0.4692.992022-02-12
CVE-2022-0302 [HIGH] CWE-416 CVE-2022-0302: Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-4177P3HIGHCVSS 8.8fixed in 108.0.5359.71≥ unspecified, < 108.0.5359.712022-11-30
CVE-2022-4177 [HIGH] CWE-416 CVE-2022-4177: Use after free in Extensions in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinc Use after free in Extensions in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install an extension to potentially exploit heap corruption via a crafted Chrome Extension and UI interaction. (Chromium security severity: High)
nvd
CVE-2023-0134P3HIGHCVSS 8.8fixed in 109.0.5414.74≥ unspecified, < 109.0.5414.742023-01-10
CVE-2023-0134 [HIGH] CWE-416 CVE-2023-0134: Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a u Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via database corruption and a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-0135P3HIGHCVSS 8.8fixed in 109.0.5414.74≥ unspecified, < 109.0.5414.742023-01-10
CVE-2023-0135 [HIGH] CWE-416 CVE-2023-0135: Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a u Use after free in Cart in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via database corruption and a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-3655P3HIGHCVSS 8.8fixed in 107.0.5304.62≥ unspecified, < 107.0.5304.622022-11-01
CVE-2022-3655 [HIGH] CWE-787 CVE-2022-3655: Heap buffer overflow in Media Galleries in Google Chrome prior to 107.0.5304.62 allowed an attacker Heap buffer overflow in Media Galleries in Google Chrome prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-2608P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2608 [HIGH] CWE-362 CVE-2022-2608: Use after free in Overview Mode in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remot Use after free in Overview Mode in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2022-3449P3HIGHCVSS 8.8fixed in 106.0.5249.119≥ unspecified, < 106.0.5249.1192022-11-09
CVE-2022-3449 [HIGH] CWE-416 CVE-2022-3449: Use after free in Safe Browsing in Google Chrome prior to 106.0.5249.119 allowed an attacker who con Use after free in Safe Browsing in Google Chrome prior to 106.0.5249.119 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase