Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 122 of 292
CVE-2026-14114P3HIGHCVSS 7.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14114 [HIGH] CWE-451 CVE-2026-14114: Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 al
Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
nvd
CVE-2026-7338P3HIGHCVSS 7.5fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7338 [HIGH] CWE-416 CVE-2026-7338: Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local net
Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
nvd
CVE-2026-7948P3HIGHCVSS 7.5fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7948 [HIGH] CWE-362 CVE-2026-7948: Race in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to pe
Race in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2009-2935P3CRITICALCVSS 10.0≤ 2.0.172.37v0.2.149.27+28 more2009-08-27
CVE-2009-2935 [CRITICAL] CWE-264 CVE-2009-2935: Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended re
Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on reading memory, and possibly obtain sensitive information or execute arbitrary code in the Chrome sandbox, via crafted JavaScript.
nvd
CVE-2012-5851P4MEDIUMCVSS 4.3PoC≤ 22.0.1229.96v22.0.1229.0+58 more2012-11-15
CVE-2012-5851 [MEDIUM] CWE-79 CVE-2012-5851: html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.
html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.
nvd
CVE-2016-5159P3HIGHCVSS 8.8≤ 52.0.2743.1162016-09-11
CVE-2016-5159 [HIGH] CWE-190 CVE-2016-5159: Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Wi
Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data that is mishandled during opj_aligned_malloc calls in dw
nvd
CVE-2012-4909P4MEDIUMCVSS 4.3PoC≤ 18.0.10253062012-09-13
CVE-2012-4909 [MEDIUM] CWE-200 CVE-2012-4909: Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information vi
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application.
nvd
CVE-2017-5091P3HIGHCVSS 8.8fixed in 60.0.3112.782017-10-27
CVE-2017-5091 [HIGH] CWE-416 CVE-2017-5091: A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, an
A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-5095P3HIGHCVSS 8.8≤ 60.0.3112.782017-10-27
CVE-2017-5095 [HIGH] CWE-787 CVE-2017-5095: Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed
Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack corruption via a crafted PDF file.
nvd
CVE-2016-1676P3HIGHCVSS 8.8≤ 50.0.2661.1022016-06-05
CVE-2016-1676 [HIGH] CWE-284 CVE-2016-1676: extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704
extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2016-5210P3HIGHCVSS 8.8≤ 54.0.2840.992017-01-19
CVE-2016-5210 [HIGH] CWE-787 CVE-2016-5210: Heap buffer overflow during TIFF image parsing in PDFium in Google Chrome prior to 55.0.2883.75 for
Heap buffer overflow during TIFF image parsing in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2018-6144P3HIGHCVSS 8.8fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6144 [HIGH] CWE-787 CVE-2018-6144: Off-by-one error in PDFium in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perfo
Off-by-one error in PDFium in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file.
nvd
CVE-2017-5099P3HIGHCVSS 8.8≤ 60.0.3112.762017-10-27
CVE-2017-5099 [HIGH] CWE-20 CVE-2017-5099: Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 f
Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to potentially gain privilege elevation via a crafted HTML page.
nvd
CVE-2019-5820P3HIGHCVSS 8.8fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5820 [HIGH] CWE-190 CVE-2019-5820: Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to pote
Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2017-5092P3HIGHCVSS 8.8fixed in 60.0.3112.782017-10-27
CVE-2017-5092 [HIGH] CWE-20 CVE-2017-5092: Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 f
Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2019-5821P3HIGHCVSS 8.8fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5821 [HIGH] CWE-190 CVE-2019-5821: Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to pote
Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2018-18359P3HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18359 [HIGH] CWE-125 CVE-2018-18359: Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remot
Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2018-6072P3HIGHCVSS 8.8fixed in 65.0.3325.1462018-11-14
CVE-2018-6072 [HIGH] CWE-190 CVE-2018-6072: An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allo
An integer overflow leading to use after free in PDFium in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2017-5122P3HIGHCVSS 8.8fixed in 61.0.3163.1002017-10-27
CVE-2017-5122 [HIGH] CWE-119 CVE-2017-5122: Inappropriate use of table size handling in V8 in Google Chrome prior to 61.0.3163.100 for Windows a
Inappropriate use of table size handling in V8 in Google Chrome prior to 61.0.3163.100 for Windows allowed a remote attacker to trigger out-of-bounds access via a crafted HTML page.
nvd
CVE-2020-6458P3HIGHCVSS 8.8fixed in 81.0.4044.122≥ unspecified, < 81.0.4044.1222020-05-21
CVE-2020-6458 [HIGH] CWE-125 CVE-2020-6458: Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote atta
Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd