cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 119 of 292
CVE-2021-30529P3HIGHCVSS 8.8fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30529 [HIGH] CWE-416 CVE-2021-30529: Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30526P3HIGHCVSS 8.8fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30526 [HIGH] CWE-787 CVE-2021-30526: Out of bounds write in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convi Out of bounds write in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2016-5196P3HIGHCVSS 8.8≤ 54.0.2840.682017-01-19
CVE-2016-5196 [HIGH] CWE-254 CVE-2016-5196: The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforc The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, including those the user was logged into, via a crafted HTML page.
nvd
CVE-2021-30552P3HIGHCVSS 8.8fixed in 91.0.4472.101≥ unspecified, < 91.0.4472.1012021-06-15
CVE-2021-30552 [HIGH] CWE-416 CVE-2021-30552: Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinc Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-5197P3HIGHCVSS 8.8≤ 54.0.2840.682017-01-19
CVE-2016-5197 [HIGH] CWE-20 CVE-2016-5197: The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML page.
nvd
CVE-2021-30527P3HIGHCVSS 8.8fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30527 [HIGH] CWE-416 CVE-2021-30527: Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a u Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30524P3HIGHCVSS 8.8fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30524 [HIGH] CWE-416 CVE-2021-30524: Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-4052P3HIGHCVSS 8.8fixed in 96.0.4664.93≥ unspecified, < 96.0.4664.932021-12-23
CVE-2021-4052 [HIGH] CWE-416 CVE-2021-4052: Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2020-16029P3HIGHCVSS 8.8fixed in 87.0.4280.66≥ unspecified, < 87.0.4280.662021-01-08
CVE-2020-16029 [HIGH] CWE-862 CVE-2020-16029: Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attac Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file.
nvd
CVE-2021-37992P3HIGHCVSS 8.8fixed in 95.0.4638.54≥ unspecified, < 95.0.4638.542021-11-02
CVE-2021-37992 [HIGH] CWE-125 CVE-2021-37992: Out of bounds read in WebAudio in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to p Out of bounds read in WebAudio in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6154P3HIGHCVSS 8.8fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-6154 [HIGH] CWE-787 CVE-2018-6154: Insufficient data validation in WebGL in Google Chrome prior to 68.0.3440.75 allowed a remote attack Insufficient data validation in WebGL in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30525P3HIGHCVSS 8.8fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30525 [HIGH] CWE-416 CVE-2021-30525: Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6131P3HIGHCVSS 8.8fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-06-27
CVE-2018-6131 [HIGH] CWE-787 CVE-2018-6131: Object lifecycle issue in WebAssembly in Google Chrome prior to 67.0.3396.62 allowed a remote attack Object lifecycle issue in WebAssembly in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30550P3HIGHCVSS 8.8fixed in 91.0.4472.101≥ unspecified, < 91.0.4472.1012021-06-15
CVE-2021-30550 [HIGH] CWE-416 CVE-2021-30550: Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who conv Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6121P3HIGHCVSS 8.8fixed in 66.0.3359.170≥ unspecified, < 66.0.3359.1702019-06-27
CVE-2018-6121 [HIGH] CWE-20 CVE-2018-6121: Insufficient validation of input in Blink in Google Chrome prior to 66.0.3359.170 allowed a remote a Insufficient validation of input in Blink in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to perform privilege escalation via a crafted HTML page.
nvd
CVE-2021-30509P3HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30509 [HIGH] CWE-787 CVE-2021-30509: Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who con Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page and a crafted Chrome extension.
nvd
CVE-2020-16022P3HIGHCVSS 8.8fixed in 87.0.4280.66≥ unspecified, < 87.0.4280.662021-01-08
CVE-2020-16022 [HIGH] CVE-2020-16022: Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remot Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially bypass firewall controls via a crafted HTML page.
nvd
CVE-2022-3046P3HIGHCVSS 8.8fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3046 [HIGH] CWE-416 CVE-2022-3046: Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convin Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-38016P3HIGHCVSS 8.8fixed in 96.0.4664.45≥ unspecified, < 96.0.4664.452021-12-23
CVE-2021-38016 [HIGH] CWE-863 CVE-2021-38016: Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2021-38017P3HIGHCVSS 8.8fixed in 96.0.4664.45≥ unspecified, < 96.0.4664.452021-12-23
CVE-2021-38017 [HIGH] CWE-863 CVE-2021-38017: Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a r Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase