cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 116 of 292
CVE-2026-13778P3HIGHCVSS 7.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13778 [HIGH] CWE-416 CVE-2026-13778: Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)
nvd
CVE-2024-3840P3HIGHCVSS 7.5fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-04-17
CVE-2024-3840 [HIGH] CWE-285 CVE-2024-3840: Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2018-17472P3CRITICALCVSS 9.6fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17472 [CRITICAL] CWE-20 CVE-2018-17472: Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.35 Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the sandbox via a crafted HTML page.
nvd
CVE-2026-1220P3HIGHCVSS 7.5fixed in 144.0.7559.99≥ 144.0.7559.99, < 144.0.7559.992026-06-10
CVE-2026-1220 [HIGH] CWE-362 CVE-2026-1220: Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-3924P3HIGHCVSS 7.5fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3924 [HIGH] CWE-416 CVE-2026-3924: use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8547P3HIGHCVSS 7.5fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8547 [HIGH] CWE-862 CVE-2026-8547: Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 all Insufficient policy enforcement in Passwords in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14115P3HIGHCVSS 7.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14115 [HIGH] CWE-20 CVE-2026-14115: Insufficient validation of untrusted input in Cast in Google Chrome prior to 150.0.7871.47 allowed a Insufficient validation of untrusted input in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-12437P3HIGHCVSS 7.5fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12437 [HIGH] CWE-416 CVE-2025-12437: Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who con Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9933P3HIGHCVSS 7.5fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9933 [HIGH] CWE-416 CVE-2026-9933: Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convi Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11149P3HIGHCVSS 7.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11149 [HIGH] CWE-20 CVE-2026-11149: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 all Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11151P3HIGHCVSS 7.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11151 [HIGH] CWE-20 CVE-2026-11151: Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827. Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-9126P3HIGHCVSS 7.5fixed in 127.0.6533.88≥ 127.0.6533.88, < 127.0.6533.882025-11-14
CVE-2024-9126 [HIGH] CWE-416 CVE-2024-9126: Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a series of curated UI gestures. (Chromium security severity: Medium)
nvd
CVE-2026-11667P3HIGHCVSS 7.5fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11667 [HIGH] CWE-125 CVE-2026-11667: Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the GPU process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-13721P3HIGHCVSS 7.5fixed in 143.0.7499.40fixed in 143.0.7499.41+1 more2025-12-02
CVE-2025-13721 [HIGH] CWE-362 CVE-2025-13721: Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11058P3HIGHCVSS 7.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11058 [HIGH] CWE-472 CVE-2026-11058: Integer overflow in CredentialProvider in Google Chrome on Windows prior to 149.0.7827.53 allowed a Integer overflow in CredentialProvider in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform OS-level privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11154P3HIGHCVSS 7.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11154 [HIGH] CWE-416 CVE-2026-11154: Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had com Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8557P3HIGHCVSS 7.5fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8557 [HIGH] CWE-416 CVE-2026-8557: Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker w Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8007P3HIGHCVSS 7.5fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8007 [HIGH] CWE-20 CVE-2026-8007: Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed a Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-15111P3HIGHCVSS 7.5fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15111 [HIGH] CWE-416 CVE-2026-15111: Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convi Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-15117P3HIGHCVSS 7.5fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15117 [HIGH] CWE-416 CVE-2026-15117: Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who co Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase