cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 115 of 292
CVE-2022-3657P3HIGHCVSS 8.8fixed in 107.0.5304.62≥ unspecified, < 107.0.5304.622022-11-01
CVE-2022-3657 [HIGH] CWE-416 CVE-2022-3657: Use after free in Extensions in Google Chrome prior to 107.0.5304.62 allowed an attacker who convinc Use after free in Extensions in Google Chrome prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2016-1662P3CRITICALCVSS 9.8≤ 50.0.2661.872016-05-14
CVE-2016-1662 [CRITICAL] CVE-2016-1662: extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback ex extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback execution once the Garbage Collection callback has started, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2022-2617P3HIGHCVSS 8.8fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2617 [HIGH] CWE-362 CVE-2022-2617: Use after free in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who con Use after free in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2026-13849P3HIGHCVSS 8.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13849 [HIGH] CWE-20 CVE-2026-13849: Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0. Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
nvd
CVE-2010-2299P3CRITICALCVSS 10.0fixed in 5.0.375.702010-06-15
CVE-2010-2299 [CRITICAL] CWE-843 CVE-2010-2299: The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375 The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 does not properly handle CBF_SMBITMAP objects in a ViewHostMsg_ClipboardWriteObjectsAsync message, which might allow remote attackers to execute arbitrary code via vectors involving crafted data from the renderer process, related to a "Type Confus
nvd
CVE-2022-0114P3HIGHCVSS 8.1fixed in 97.0.4692.71≥ unspecified, < 97.0.4692.712022-02-12
CVE-2022-0114 [HIGH] CWE-125 CVE-2022-0114: Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a rem Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.
nvd
CVE-2023-4761P3HIGHCVSS 8.1fixed in 116.0.5845.179≥ 116.0.5845.179, < 116.0.5845.1792023-09-05
CVE-2023-4761 [HIGH] CWE-125 CVE-2023-4761: Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attac Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2011-2806P3CRITICALCVSS 10.0fixed in 13.0.782.2152011-08-29
CVE-2011-2806 [CRITICAL] CWE-119 CVE-2011-2806: Google Chrome before 13.0.782.215 on Windows does not properly handle vertex data, which allows remo Google Chrome before 13.0.782.215 on Windows does not properly handle vertex data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2016-1639P3CRITICALCVSS 9.8≤ 48.0.2564.1162016-03-06
CVE-2016-1639 [CRITICAL] CVE-2016-1639: Use-after-free vulnerability in browser/extensions/api/webrtc_audio_private/webrtc_audio_private_api Use-after-free vulnerability in browser/extensions/api/webrtc_audio_private/webrtc_audio_private_api.cc in the WebRTC Audio Private API implementation in Google Chrome before 49.0.2623.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect reliance on the resource context pointer.
nvd
CVE-2009-2555P3CRITICALCVSS 9.3≤ 2.0.172.33v0.2.149.29+26 more2009-07-21
CVE-2009-2555 [CRITICAL] CWE-119 CVE-2009-2555: Heap-based buffer overflow in src/jsregexp.cc in Google V8 before 1.1.10.14, as used in Google Chrom Heap-based buffer overflow in src/jsregexp.cc in Google V8 before 1.1.10.14, as used in Google Chrome before 2.0.172.37, allows remote attackers to execute arbitrary code in the Chrome sandbox via a crafted JavaScript regular expression.
nvd
CVE-2025-0997P3HIGHCVSS 8.1fixed in 133.0.6943.98≥ 133.0.6943.98, < 133.0.6943.982025-02-15
CVE-2025-0997 [HIGH] CWE-416 CVE-2025-0997: Use after free in Navigation in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to po Use after free in Navigation in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2026-17869P3HIGHCVSS 8.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17869 [HIGH] CWE-125 CVE-2026-17869: Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to per Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17995P3HIGHCVSS 8.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17995 [HIGH] CWE-125 CVE-2026-17995: Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perf Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2016-1706P3CRITICALCVSS 9.6≤ 51.0.2704.1062016-07-23
CVE-2016-1706 [CRITICAL] CWE-20 CVE-2016-1706: The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC me The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_hos
nvd
CVE-2026-5915P3HIGHCVSS 8.1fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5915 [HIGH] CWE-20 CVE-2026-5915: Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11693P3HIGHCVSS 8.1fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11693 [HIGH] CWE-346 CVE-2026-11693: Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote at Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2010-4041P3CRITICALCVSS 9.8fixed in 7.0.517.412010-10-21
CVE-2010-4041 [CRITICAL] CVE-2010-4041: The sandbox implementation in Google Chrome before 7.0.517.41 on Linux does not properly constrain w The sandbox implementation in Google Chrome before 7.0.517.41 on Linux does not properly constrain worker processes, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2026-13778P3HIGHCVSS 7.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13778 [HIGH] CWE-416 CVE-2026-13778: Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)
nvd
CVE-2024-3840P3HIGHCVSS 7.5fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-04-17
CVE-2024-3840 [HIGH] CWE-285 CVE-2024-3840: Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2018-17472P3CRITICALCVSS 9.6fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17472 [CRITICAL] CWE-20 CVE-2018-17472: Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.35 Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the sandbox via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase