Google Chrome vulnerabilities

3,975 known vulnerabilities affecting google/chrome.

Total CVEs
3,975
CISA KEV
74
actively exploited
Public exploits
63
Exploited in wild
65
Severity breakdown
CRITICAL297HIGH2024MEDIUM1626LOW17UNKNOWN11

Vulnerabilities

Page 115 of 199
CVE-2018-6117MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6117 [MEDIUM] CWE-200 CVE-2018-6117: Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to Confusing settings in Autofill in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2018-6096MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6096 [MEDIUM] CWE-20 CVE-2018-6096: A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
nvd
CVE-2018-6109MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6109 [MEDIUM] CWE-200 CVE-2018-6109: readAsText() can indefinitely read the file picked by the user, rather than only once at the time th readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page.
nvd
CVE-2018-6165MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6165 [MEDIUM] CVE-2018-6165: Incorrect handling of reloads in Navigation in Google Chrome prior to 68.0.3440.75 allowed a remote Incorrect handling of reloads in Navigation in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-6137MEDIUMCVSS 6.5fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6137 [MEDIUM] CWE-200 CVE-2018-6137: CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cros CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-16080MEDIUMCVSS 6.5fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16080 [MEDIUM] CWE-20 CVE-2018-16080: A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497 A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-6093MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6093 [MEDIUM] CWE-200 CVE-2018-6093: Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacke Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6123MEDIUMCVSS 6.5fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6123 [MEDIUM] CWE-416 CVE-2018-6123: A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potent A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-20070MEDIUMCVSS 6.5fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802019-01-09
CVE-2018-20070 [MEDIUM] CWE-20 CVE-2018-20070: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2018-6133MEDIUMCVSS 6.5fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6133 [MEDIUM] CWE-19 CVE-2018-6133: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 67.0.3396.62 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-16079MEDIUMCVSS 5.3fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16079 [MEDIUM] CWE-362 CVE-2018-16079: A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69. A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-16088MEDIUMCVSS 6.5fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16088 [MEDIUM] CWE-20 CVE-2018-16088: A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowe A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to download arbitrary files with no user input via a crafted HTML page.
nvd
CVE-2018-6172MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6172 [MEDIUM] CVE-2018-6172: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6173MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6173 [MEDIUM] CVE-2018-6173: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6100MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6100 [MEDIUM] CWE-19 CVE-2018-6100: Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0 Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-16087MEDIUMCVSS 4.3fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16087 [MEDIUM] CWE-732 CVE-2018-16087: Lack of proper state tracking in Permissions in Google Chrome prior to 69.0.3497.81 allowed a remote Lack of proper state tracking in Permissions in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2018-6179MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6179 [MEDIUM] CWE-200 CVE-2018-6179: Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chr Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.
nvd
CVE-2018-6135MEDIUMCVSS 6.5fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6135 [MEDIUM] CVE-2018-6135: Lack of clearing the previous site before loading alerts from a new one in Blink in Google Chrome pr Lack of clearing the previous site before loading alerts from a new one in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2018-20346HIGHCVSS 8.1fixed in 71.0.3578.802018-12-21
CVE-2018-20346 [HIGH] CWE-190 CVE-2018-20346: SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and result SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magell
nvd
CVE-2018-18336HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18336 [HIGH] CWE-416 CVE-2018-18336: Incorrect object lifecycle in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacke Incorrect object lifecycle in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd