cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 117 of 292
CVE-2026-3932P3HIGHCVSS 7.5fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3932 [HIGH] CWE-284 CVE-2026-3932: Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7343P3HIGHCVSS 7.5fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7343 [HIGH] CWE-416 CVE-2026-7343: Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacke Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-9990P3HIGHCVSS 7.5fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9990 [HIGH] CWE-416 CVE-2026-9990: Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote at Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-6509P3CRITICALCVSS 9.6fixed in 83.0.4103.116≥ unspecified, < 83.0.4103.1162020-07-22
CVE-2020-6509 [CRITICAL] CWE-416 CVE-2020-6509: Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinc Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2017-5077P3HIGHCVSS 8.8fixed in 59.0.3071.86fixed in 59.0.3071.922017-10-27
CVE-2017-5077 [HIGH] CWE-125 CVE-2017-5077: Insufficient validation of untrusted input in Skia in Google Chrome prior to 59.0.3071.86 for Linux, Insufficient validation of untrusted input in Skia in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2016-1667P3HIGHCVSS 8.8≤ 50.0.2661.872016-05-14
CVE-2016-1667 [HIGH] CWE-284 CVE-2016-1667: The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementat The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2017-5133P3HIGHCVSS 8.8fixed in 62.0.3202.622018-02-07
CVE-2017-5133 [HIGH] CWE-787 CVE-2017-5133: Off-by-one read/write on the heap in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote a Off-by-one read/write on the heap in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to corrupt memory and possibly leak information and potentially execute code via a crafted PDF file.
nvd
CVE-2016-1697P3HIGHCVSS 8.8≤ 51.0.2704.632016-06-05
CVE-2016-1697 [HIGH] CWE-284 CVE-2016-1697: The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used i The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
nvd
CVE-2017-15388P3HIGHCVSS 8.8fixed in 62.0.3202.622018-02-07
CVE-2017-15388 [HIGH] CWE-125 CVE-2017-15388: Iteration through non-finite points in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote Iteration through non-finite points in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2019-5791P3HIGHCVSS 8.8fixed in 73.0.3683.75vprior to 73.0.3683.752019-05-23
CVE-2019-5791 [HIGH] CWE-125 CVE-2019-5791: Inappropriate optimization in V8 in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to Inappropriate optimization in V8 in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-15408P3HIGHCVSS 8.8fixed in 63.0.3239.842018-08-28
CVE-2017-15408 [HIGH] CWE-119 CVE-2017-15408: Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file that is mishandled by PDFium.
nvd
CVE-2019-13736P3HIGHCVSS 8.8fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13736 [HIGH] CWE-190 CVE-2019-13736: Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to poten Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2016-1672P3HIGHCVSS 8.8≤ 50.0.2661.1022016-06-05
CVE-2016-1672 [HIGH] CWE-254 CVE-2016-1672: The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extensio The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which allows remote attackers to conduct bindings-interception attacks and bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2016-1675P3HIGHCVSS 8.8≤ 50.0.2661.1022016-06-05
CVE-2016-1675 [HIGH] CWE-284 CVE-2016-1675: Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Orig Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.
nvd
CVE-2018-6057P3HIGHCVSS 8.8fixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6057 [HIGH] CWE-732 CVE-2018-6057: Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote at Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to bypass inter-process read only guarantees via a crafted HTML page.
nvd
CVE-2018-18341P3HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18341 [HIGH] CWE-190 CVE-2018-18341: An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.8 An integer overflow leading to a heap buffer overflow in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13727P3HIGHCVSS 8.8fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13727 [HIGH] CWE-281 CVE-2019-13727: Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remot Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2018-6054P3HIGHCVSS 8.8fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6054 [HIGH] CWE-416 CVE-2018-6054: Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potenti Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2017-5129P3HIGHCVSS 8.8fixed in 62.0.3202.622018-02-07
CVE-2017-5129 [HIGH] CWE-416 CVE-2017-5129: A use after free in WebAudio in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attack A use after free in WebAudio in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2018-18354P3HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18354 [HIGH] CWE-20 CVE-2018-18354: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior t Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase