Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 120 of 292
CVE-2021-30543P3HIGHCVSS 8.8fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30543 [HIGH] CWE-416 CVE-2021-30543: Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced
Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30542P3HIGHCVSS 8.8fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30542 [HIGH] CWE-416 CVE-2021-30542: Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced
Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2011-1805P3HIGHCVSS 8.8fixed in 11.0.0.0≥ unspecified, < 11.0.0.02020-06-03
CVE-2011-1805 [HIGH] CWE-704 CVE-2011-1805: Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a remote attacker to potentially exploit
Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6419P3HIGHCVSS 8.8fixed in 81.0.4044.92≥ unspecified, < 81.0.4044.922020-06-03
CVE-2020-6419 [HIGH] CWE-787 CVE-2020-6419: Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potent
Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0793P3HIGHCVSS 8.8fixed in 99.0.4844.51≥ unspecified, < 99.0.4844.512022-04-05
CVE-2022-0793 [HIGH] CWE-416 CVE-2022-0793: Use after free in Cast in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a us
Use after free in Cast in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2022-1876P3HIGHCVSS 8.8fixed in 102.0.5005.61≥ unspecified, < 102.0.5005.612022-07-27
CVE-2022-1876 [HIGH] CWE-787 CVE-2022-1876: Heap buffer overflow in DevTools in Google Chrome prior to 102.0.5005.61 allowed an attacker who con
Heap buffer overflow in DevTools in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0798P3HIGHCVSS 8.8fixed in 99.0.4844.51≥ unspecified, < 99.0.4844.512022-04-05
CVE-2022-0798 [HIGH] CWE-416 CVE-2022-0798: Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinc
Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2022-0980P3HIGHCVSS 8.8fixed in 99.0.4844.74≥ unspecified, < 99.0.4844.742022-07-22
CVE-2022-0980 [HIGH] CWE-416 CVE-2022-0980: Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convin
Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific user interactions.
nvd
CVE-2022-1864P3HIGHCVSS 8.8fixed in 102.0.5005.61≥ unspecified, < 102.0.5005.612022-07-27
CVE-2022-1864 [HIGH] CWE-416 CVE-2022-1864: Use after free in WebApp Installs in Google Chrome prior to 102.0.5005.61 allowed an attacker who co
Use after free in WebApp Installs in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.
nvd
CVE-2022-1865P3HIGHCVSS 8.8fixed in 102.0.5005.61≥ unspecified, < 102.0.5005.612022-07-27
CVE-2022-1865 [HIGH] CWE-416 CVE-2022-1865: Use after free in Bookmarks in Google Chrome prior to 102.0.5005.61 allowed an attacker who convince
Use after free in Bookmarks in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.
nvd
CVE-2022-1863P3HIGHCVSS 8.8fixed in 102.0.5005.61≥ unspecified, < 102.0.5005.612022-07-27
CVE-2022-1863 [HIGH] CWE-416 CVE-2022-1863: Use after free in Tab Groups in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinc
Use after free in Tab Groups in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.
nvd
CVE-2023-0474P3HIGHCVSS 8.8fixed in 109.0.5414.119≥ unspecified, < 109.0.5414.1192023-01-30
CVE-2023-0474 [HIGH] CWE-416 CVE-2023-0474: Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an attacker who convinc
Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a Chrome web app. (Chromium security severity: Medium)
nvd
CVE-2015-6792P3CRITICALCVSS 9.8≤ 47.0.2526.802015-12-24
CVE-2015-6792 [CRITICAL] CVE-2015-6792: The MIDI subsystem in Google Chrome before 47.0.2526.106 does not properly handle the sending of dat
The MIDI subsystem in Google Chrome before 47.0.2526.106 does not properly handle the sending of data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to midi_manager.cc, midi_manager_alsa.cc, and midi_manager_mac.cc, a different vulnerability than CVE-2015-8664.
nvd
CVE-2010-1770P3CRITICALCVSS 9.3fixed in 5.0.375.702010-06-11
CVE-2010-1770 [CRITICAL] CWE-94 CVE-2010-1770: WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption
nvd
CVE-2026-11158P3HIGHCVSS 8.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11158 [HIGH] CWE-20 CVE-2026-11158: Insufficient validation of untrusted input in Downloads in Google Chrome on Mac prior to 149.0.7827.
Insufficient validation of untrusted input in Downloads in Google Chrome on Mac prior to 149.0.7827.53 allowed a local attacker to potentially perform a sandbox escape via a crafted AppleScript command. (Chromium security severity: Medium)
nvd
CVE-2021-21177P3MEDIUMCVSS 6.5fixed in 89.0.4389.72≥ unspecified, < 89.0.4389.722021-03-09
CVE-2021-21177 [MEDIUM] CWE-732 CVE-2021-21177: Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote
Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2018-6101P3HIGHCVSS 7.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172018-12-04
CVE-2018-6101 [HIGH] CWE-20 CVE-2018-6101: A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attac
A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server.
nvd
CVE-2024-11114P3HIGHCVSS 8.3fixed in 131.0.6778.69≥ 131.0.6778.69, < 131.0.6778.692024-11-12
CVE-2024-11114 [HIGH] CVE-2024-11114: Inappropriate implementation in Views in Google Chrome on Windows prior to 131.0.6778.69 allowed a r
Inappropriate implementation in Views in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2016-1633P3CRITICALCVSS 9.8≤ 48.0.2564.1162016-03-06
CVE-2016-1633 [CRITICAL] CVE-2016-1633: Use-after-free vulnerability in Blink, as used in Google Chrome before 49.0.2623.75, allows remote a
Use-after-free vulnerability in Blink, as used in Google Chrome before 49.0.2623.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2024-10229P3HIGHCVSS 8.1fixed in 130.0.6723.69≥ 130.0.6723.69, < 130.0.6723.692024-10-22
CVE-2024-10229 [HIGH] CVE-2024-10229: Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote
Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: High)
nvd