Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 121 of 292
CVE-2011-3047P3CRITICALCVSS 9.3fixed in 17.0.963.792012-03-10
CVE-2011-3047 [CRITICAL] CWE-119 CVE-2011-3047: The GPU process in Google Chrome before 17.0.963.79 allows remote attackers to execute arbitrary cod
The GPU process in Google Chrome before 17.0.963.79 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) by leveraging an error in the plug-in loading mechanism.
nvd
CVE-2026-13819P3HIGHCVSS 8.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13819 [HIGH] CWE-125 CVE-2026-13819: Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker
Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11015P3HIGHCVSS 8.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11015 [HIGH] CWE-125 CVE-2026-11015: Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to pe
Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11169P3HIGHCVSS 8.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11169 [HIGH] CWE-91 CVE-2026-11169: Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacke
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted XML file. (Chromium security severity: Medium)
nvd
CVE-2026-5913P3HIGHCVSS 8.1fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5913 [HIGH] CWE-125 CVE-2026-5913: Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to per
Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2021-21123P3MEDIUMCVSS 6.5fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21123 [MEDIUM] CWE-20 CVE-2021-21123: Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a rem
Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
nvd
CVE-2026-17654P3HIGHCVSS 7.8≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17654 [HIGH] CWE-362 CVE-2026-17654: Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform O
Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)
nvd
CVE-2026-16414P3HIGHCVSS 7.8fixed in 150.0.7871.182≥ 150.0.7871.182, < 150.0.7871.1822026-07-21
CVE-2026-16414 [HIGH] CWE-20 CVE-2026-16414: Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 al
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
nvd
CVE-2026-17861P3HIGHCVSS 7.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17861 [HIGH] CWE-20 CVE-2026-17861: Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowe
Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-17862P3HIGHCVSS 7.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17862 [HIGH] CWE-416 CVE-2026-17862: Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacke
Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-17864P3HIGHCVSS 7.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17864 [HIGH] CWE-269 CVE-2026-17864: Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a loc
Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2019-5759P3CRITICALCVSS 9.6fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5759 [CRITICAL] CWE-416 CVE-2019-5759: Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.
Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2011-2075P3CRITICALCVSS 9.3v11.0.696.65v12.0.742.302011-05-10
CVE-2011-2075 [CRITICAL] CVE-2011-2075: Unspecified vulnerability in Google Chrome 11.0.696.65 on Windows 7 SP1 allows remote attackers to e
Unspecified vulnerability in Google Chrome 11.0.696.65 on Windows 7 SP1 allows remote attackers to execute arbitrary code via unknown vectors. NOTE: as of 20110510, the only disclosure is a vague advisory that possibly relates to multiple vulnerabilities or multiple products. However, because it is from a well-known researcher, it is being assigned a CVE id
nvd
CVE-2024-0804P3HIGHCVSS 7.5fixed in 121.0.6167.85≥ 121.0.6167.85, < 121.0.6167.852024-01-24
CVE-2024-0804 [HIGH] CWE-693 CVE-2024-0804: Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a
Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5277P3HIGHCVSS 7.5fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5277 [HIGH] CWE-472 CVE-2026-5277: Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attac
Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-12726P3HIGHCVSS 7.5fixed in 142.0.7444.134≥ 142.0.7444.137, < 142.0.7444.1372025-11-10
CVE-2025-12726 [HIGH] CWE-269 CVE-2025-12726: Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a
Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11239P3HIGHCVSS 7.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11239 [HIGH] CWE-20 CVE-2026-11239: Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-8510P3HIGHCVSS 7.5fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8510 [HIGH] CWE-472 CVE-2026-8510: Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attack
Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-9123P3HIGHCVSS 7.5fixed in 148.0.7778.179≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9123 [HIGH] CWE-122 CVE-2026-9123: Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.
Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium)
nvd
CVE-2026-11296P3HIGHCVSS 7.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11296 [HIGH] CWE-269 CVE-2026-11296: Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remot
Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
nvd