cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 118 of 292
CVE-2018-18339P3HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18339 [HIGH] CWE-416 CVE-2018-18339: Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 allowed a remote attac Incorrect object lifecycle in WebAudio in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-18338P3HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18338 [HIGH] CWE-787 CVE-2018-18338: Incorrect, thread-unsafe use of SkImage in Canvas in Google Chrome prior to 71.0.3578.80 allowed a r Incorrect, thread-unsafe use of SkImage in Canvas in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6454P3HIGHCVSS 8.8fixed in 81.0.4044.92≥ unspecified, < 81.0.4044.922020-04-13
CVE-2020-6454 [HIGH] CWE-416 CVE-2020-6454: Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convince Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2018-18340P3HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18340 [HIGH] CWE-416 CVE-2018-18340: Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote Incorrect object lifecycle in MediaRecorder in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-18343P3HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18343 [HIGH] CWE-416 CVE-2018-18343: Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.8 Incorrect handing of paths leading to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-15387P3HIGHCVSS 8.8fixed in 62.0.3202.622018-02-07
CVE-2017-15387 [HIGH] CVE-2017-15387: Insufficient enforcement of Content Security Policy in Blink in Google Chrome prior to 62.0.3202.62 Insufficient enforcement of Content Security Policy in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to open javascript: URL windows when they should not be allowed to via a crafted HTML page.
nvd
CVE-2019-5824P3HIGHCVSS 8.8fixed in 74.0.3729.131≥ unspecified, < 74.0.3729.1312019-06-27
CVE-2019-5824 [HIGH] CWE-787 CVE-2019-5824: Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker t Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5064P3HIGHCVSS 8.8fixed in 58.0.3029.812017-10-27
CVE-2017-5064 [HIGH] CWE-119 CVE-2017-5064: Incorrect handling of DOM changes in Blink in Google Chrome prior to 58.0.3029.81 for Windows allowe Incorrect handling of DOM changes in Blink in Google Chrome prior to 58.0.3029.81 for Windows allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-17474P3HIGHCVSS 8.8fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17474 [HIGH] CWE-416 CVE-2018-17474: Use after free in HTMLImportsController in Blink in Google Chrome prior to 70.0.3538.67 allowed a re Use after free in HTMLImportsController in Blink in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-5149P3HIGHCVSS 8.8≤ 52.0.2743.1162016-09-11
CVE-2016-5149 [HIGH] CWE-94 CVE-2016-5149: The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.27 The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to identify an associated extension, which allows remote attackers to conduct extension-bindings injection attacks by leveraging script access to a resource that initially has the about:blank URL.
nvd
CVE-2016-1632P3HIGHCVSS 8.8≤ 48.0.2564.1162016-03-06
CVE-2016-1632 [HIGH] CWE-264 CVE-2016-1632: The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own propert The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.
nvd
CVE-2017-5126P3HIGHCVSS 8.8fixed in 62.0.3202.622018-02-07
CVE-2017-5126 [HIGH] CWE-416 CVE-2017-5126: A use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to poten A use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2020-6420P3HIGHCVSS 8.8fixed in 80.0.3987.132≥ unspecified, < 80.0.3987.1322020-03-23
CVE-2020-6420 [HIGH] CVE-2020-6420: Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote at Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2016-5182P3HIGHCVSS 8.8≤ 53.0.2785.1432016-12-18
CVE-2016-5182 [HIGH] CWE-119 CVE-2016-5182: Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android h Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation in bitmap handling, which allowed a remote attacker to potentially exploit heap corruption via crafted HTML pages.
nvd
CVE-2016-1696P3HIGHCVSS 8.8≤ 51.0.2704.632016-06-05
CVE-2016-1696 [HIGH] CWE-254 CVE-2016-1696: The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings ac The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2017-5062P3HIGHCVSS 8.8fixed in 58.0.3029.81fixed in 58.0.3029.832017-10-27
CVE-2017-5062 [HIGH] CWE-416 CVE-2017-5062: A use after free in Chrome Apps in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, A use after free in Chrome Apps in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to potentially perform out of bounds memory access via a crafted Chrome extension.
nvd
CVE-2020-6379P3HIGHCVSS 8.8fixed in 79.0.3945.130≥ unspecified, < 79.0.3945.1302020-02-11
CVE-2020-6379 [HIGH] CWE-416 CVE-2020-6379: Use after free in V8 in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentiall Use after free in V8 in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30507P3HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30507 [HIGH] CWE-829 CVE-2021-30507: Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2022-0608P3HIGHCVSS 8.8fixed in 98.0.4758.102≥ unspecified, < 98.0.4758.1022022-04-05
CVE-2022-0608 [HIGH] CWE-190 CVE-2022-0608: Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potent Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13699P3HIGHCVSS 8.8fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13699 [HIGH] CWE-416 CVE-2019-13699: Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had com Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase