Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 123 of 292
CVE-2016-5209P3HIGHCVSS 8.8≤ 54.0.2840.992017-01-19
CVE-2016-5209 [HIGH] CWE-787 CVE-2016-5209: Bad casting in bitmap manipulation in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows
Bad casting in bitmap manipulation in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5806P3HIGHCVSS 8.8fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5806 [HIGH] CWE-190 CVE-2019-5806: Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attack
Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5811P3HIGHCVSS 8.8fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5811 [HIGH] CVE-2019-5811: Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote
Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2015-6764P3CRITICALCVSS 9.8≤ 46.0.2490.862015-12-06
CVE-2015-6764 [CRITICAL] CWE-119 CVE-2015-6764: The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in
The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2019-13721P3HIGHCVSS 8.8fixed in 78.0.3904.87≥ unspecified, < 78.0.3904.872019-11-25
CVE-2019-13721 [HIGH] CWE-416 CVE-2019-13721: Use after free in PDFium in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potenti
Use after free in PDFium in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-5184P3HIGHCVSS 8.8≤ 53.0.2785.1432016-12-18
CVE-2016-5184 [HIGH] CWE-416 CVE-2016-5184: PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android
PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles in CFFL_FormFillter::KillFocusForAnnot, which allowed a remote attacker to potentially exploit heap corruption via crafted PDF files.
nvd
CVE-2018-17478P3HIGHCVSS 8.8fixed in 70.0.3538.102≥ unspecified, < 70.0.3538.1022019-06-27
CVE-2018-17478 [HIGH] CWE-129 CVE-2018-17478: Incorrect array position calculations in V8 in Google Chrome prior to 70.0.3538.102 allowed a remote
Incorrect array position calculations in V8 in Google Chrome prior to 70.0.3538.102 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
nvd
CVE-2019-5783P3HIGHCVSS 8.8fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5783 [HIGH] CWE-20 CVE-2019-5783: Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a
Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Injection attack via a crafted HTML page.
nvd
CVE-2020-6459P3HIGHCVSS 8.8fixed in 81.0.4044.122≥ unspecified, < 81.0.4044.1222020-05-21
CVE-2020-6459 [HIGH] CWE-416 CVE-2020-6459: Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to pote
Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30586P3HIGHCVSS 8.8fixed in 92.0.4515.107≥ unspecified, < 92.0.4515.1072021-08-03
CVE-2021-30586 [HIGH] CWE-416 CVE-2021-30586: Use after free in dialog box handling in Windows in Google Chrome prior to 92.0.4515.107 allowed an
Use after free in dialog box handling in Windows in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-4055P3HIGHCVSS 8.8fixed in 96.0.4664.93≥ unspecified, < 96.0.4664.932021-12-23
CVE-2021-4055 [HIGH] CWE-787 CVE-2021-4055: Heap buffer overflow in extensions in Google Chrome prior to 96.0.4664.93 allowed an attacker who co
Heap buffer overflow in extensions in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2019-5877P3HIGHCVSS 8.8fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-5877 [HIGH] CWE-787 CVE-2019-5877: Out of bounds memory access in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote at
Out of bounds memory access in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5853P3HIGHCVSS 8.8fixed in 76.0.3809.87≥ unspecified, < 76.0.3809.872019-11-25
CVE-2019-5853 [HIGH] CWE-682 CVE-2019-5853: Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote a
Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13695P3HIGHCVSS 8.8fixed in 77.0.3865.120≥ unspecified, < 77.0.3865.1202019-11-25
CVE-2019-13695 [HIGH] CWE-416 CVE-2019-13695: Use after free in audio in Google Chrome on Android prior to 77.0.3865.120 allowed a remote attacker
Use after free in audio in Google Chrome on Android prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5851P3HIGHCVSS 8.8fixed in 76.0.3809.87≥ unspecified, < 76.0.3809.872019-11-25
CVE-2019-5851 [HIGH] CWE-416 CVE-2019-5851: Use after free in WebAudio in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to poten
Use after free in WebAudio in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30519P3HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30519 [HIGH] CWE-416 CVE-2021-30519: Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced
Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious payments app to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5859P3HIGHCVSS 8.8fixed in 76.0.3809.87≥ unspecified, < 76.0.3809.872019-11-25
CVE-2019-5859 [HIGH] CVE-2019-5859: Insufficient filtering in URI schemes in Google Chrome on Windows prior to 76.0.3809.87 allowed a re
Insufficient filtering in URI schemes in Google Chrome on Windows prior to 76.0.3809.87 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2019-5876P3HIGHCVSS 8.8fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-5876 [HIGH] CWE-416 CVE-2019-5876: Use after free in media in Google Chrome on Android prior to 77.0.3865.75 allowed a remote attacker
Use after free in media in Google Chrome on Android prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13694P3HIGHCVSS 8.8fixed in 77.0.3865.120≥ unspecified, < 77.0.3865.1202019-11-25
CVE-2019-13694 [HIGH] CWE-416 CVE-2019-13694: Use after free in WebRTC in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potent
Use after free in WebRTC in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13687P3HIGHCVSS 8.8fixed in 77.0.3865.90≥ unspecified, < 77.0.3865.902019-11-25
CVE-2019-13687 [HIGH] CWE-416 CVE-2019-13687: Use after free in Blink in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentia
Use after free in Blink in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd