Google Chrome vulnerabilities
5,463 known vulnerabilities affecting google/chrome.
Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65
Vulnerabilities
Page 12 of 274
CVE-2026-13869P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13869 [CRITICAL] CWE-416 CVE-2026-13869: Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacke
Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-15773P3CRITICALCVSS 9.6fixed in 150.0.7871.125≥ 150.0.7871.125, < 150.0.7871.1252026-07-14
CVE-2026-15773 [CRITICAL] CWE-416 CVE-2026-15773: Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker
Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2013-6166P4MEDIUMCVSS 6.8PoC≤ 28.0.1500.952014-02-15
CVE-2013-6166 [MEDIUM] CWE-352 CVE-2013-6166: Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the requir
Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that forces a web application to set a malformed cookie within an HTTP response.
nvd
CVE-2012-2897P3HIGHCVSS 7.8≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2897 [HIGH] CWE-119 CVE-2012-2897: The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers t
nvd
CVE-2026-9111P3HIGHCVSS 8.8fixed in 148.0.7778.179≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9111 [HIGH] CWE-416 CVE-2026-9111: Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker
Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-5865P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5865 [HIGH] CWE-843 CVE-2026-5865: Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute ar
Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9112P3HIGHCVSS 8.8fixed in 148.0.7778.179≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9112 [HIGH] CWE-416 CVE-2026-9112: Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker
Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10914P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10914 [HIGH] CWE-416 CVE-2026-10914: Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker
Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10913P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10913 [HIGH] CWE-416 CVE-2026-10913: Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker
Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8526P3HIGHCVSS 8.8fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8526 [HIGH] CWE-787 CVE-2026-8526: Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8524P3HIGHCVSS 8.8fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8524 [HIGH] CWE-787 CVE-2026-8524: Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker t
Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7951P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7951 [HIGH] CWE-787 CVE-2026-7951: Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to e
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-9114P3HIGHCVSS 8.8fixed in 148.0.7778.179≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9114 [HIGH] CWE-416 CVE-2026-9114: Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to exec
Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)
nvd
CVE-2026-10893P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10893 [HIGH] CWE-416 CVE-2026-10893: Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to ex
Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
nvd
CVE-2026-11147P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11147 [HIGH] CWE-416 CVE-2026-11147: Use after free in WebML in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker
Use after free in WebML in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-15776P3HIGHCVSS 8.8fixed in 150.0.7871.125≥ 150.0.7871.125, < 150.0.7871.1252026-07-14
CVE-2026-15776 [HIGH] CWE-843 CVE-2026-15776: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacke
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13033P3HIGHCVSS 8.8fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13033 [HIGH] CWE-125 CVE-2026-13033: Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowe
Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-16421P3HIGHCVSS 8.8fixed in 150.0.7871.182≥ 150.0.7871.182, < 150.0.7871.1822026-07-21
CVE-2026-16421 [HIGH] CWE-20 CVE-2026-16421: Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote a
Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10978P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10978 [HIGH] CWE-416 CVE-2026-10978: Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote att
Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
nvd
CVE-2026-15903P3HIGHCVSS 8.8fixed in 150.0.7871.128≥ 150.0.7871.128, < 150.0.7871.1282026-07-20
CVE-2026-15903 [HIGH] CWE-125 CVE-2026-15903: Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacke
Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd