Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 124 of 292
CVE-2019-13688P3HIGHCVSS 8.8fixed in 77.0.3865.90≥ unspecified, < 77.0.3865.902019-11-25
CVE-2019-13688 [HIGH] CWE-416 CVE-2019-13688: Use after free in Blink in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentia
Use after free in Blink in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13686P3HIGHCVSS 8.8fixed in 77.0.3865.90≥ unspecified, < 77.0.3865.902019-11-25
CVE-2019-13686 [HIGH] CWE-416 CVE-2019-13686: Use after free in offline mode in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to p
Use after free in offline mode in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13685P3HIGHCVSS 8.8fixed in 77.0.3865.90≥ unspecified, < 77.0.3865.902019-11-25
CVE-2019-13685 [HIGH] CWE-416 CVE-2019-13685: Use after free in sharing view in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to p
Use after free in sharing view in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5874P3HIGHCVSS 8.8fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-5874 [HIGH] CVE-2019-5874: Insufficient filtering in URI schemes in Google Chrome on Windows prior to 77.0.3865.75 allowed a re
Insufficient filtering in URI schemes in Google Chrome on Windows prior to 77.0.3865.75 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2018-17479P3HIGHCVSS 8.8fixed in 70.0.3538.110≥ unspecified, < 70.0.3538.1102019-06-27
CVE-2018-17479 [HIGH] CWE-416 CVE-2018-17479: Incorrect object lifetime calculations in GPU code in Google Chrome prior to 70.0.3538.110 allowed a
Incorrect object lifetime calculations in GPU code in Google Chrome prior to 70.0.3538.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-16070P3HIGHCVSS 8.8fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-06-27
CVE-2018-16070 [HIGH] CWE-190 CVE-2018-16070: Integer overflows in Skia in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potent
Integer overflows in Skia in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13698P3HIGHCVSS 8.8fixed in 73.0.3683.103≥ unspecified, < 73.0.3683.1032019-11-25
CVE-2019-13698 [HIGH] CWE-787 CVE-2019-13698: Out of bounds memory access in JavaScript in Google Chrome prior to 73.0.3683.103 allowed a remote a
Out of bounds memory access in JavaScript in Google Chrome prior to 73.0.3683.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30520P3HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30520 [HIGH] CWE-416 CVE-2021-30520: Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convince
Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5878P3HIGHCVSS 8.8fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-5878 [HIGH] CWE-416 CVE-2019-5878: Use after free in V8 in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially
Use after free in V8 in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21144P3HIGHCVSS 8.8fixed in 88.0.4324.146≥ unspecified, < 88.0.4324.1462021-02-09
CVE-2021-21144 [HIGH] CWE-787 CVE-2021-21144: Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who c
Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2018-6156P3HIGHCVSS 8.8fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-6156 [HIGH] CWE-787 CVE-2018-6156: Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a re
Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
nvd
CVE-2019-5871P3HIGHCVSS 8.8fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-5871 [HIGH] CWE-787 CVE-2019-5871: Heap buffer overflow in Skia in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to pot
Heap buffer overflow in Skia in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5843P3HIGHCVSS 8.8fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-12-10
CVE-2019-5843 [HIGH] CWE-787 CVE-2019-5843: Out of bounds memory access in JavaScript in Google Chrome prior to 74.0.3729.108 allowed a remote a
Out of bounds memory access in JavaScript in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6157P3HIGHCVSS 8.8fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-6157 [HIGH] CWE-704 CVE-2018-6157: Type confusion in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potenti
Type confusion in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
nvd
CVE-2021-21143P3HIGHCVSS 8.8fixed in 88.0.4324.146≥ unspecified, < 88.0.4324.1462021-02-09
CVE-2021-21143 [HIGH] CWE-787 CVE-2021-21143: Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who c
Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2019-5841P3HIGHCVSS 8.8fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-12-10
CVE-2019-5841 [HIGH] CWE-787 CVE-2019-5841: Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote at
Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5856P3HIGHCVSS 8.8fixed in 76.0.3809.87≥ unspecified, < 76.0.3809.872019-11-25
CVE-2019-5856 [HIGH] CWE-20 CVE-2019-5856: Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote a
Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2019-13696P3HIGHCVSS 8.8fixed in 77.0.3865.120≥ unspecified, < 77.0.3865.1202019-11-25
CVE-2019-13696 [HIGH] CWE-416 CVE-2019-13696: Use after free in JavaScript in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to po
Use after free in JavaScript in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6149P3HIGHCVSS 8.8fixed in 67.0.3396.87≥ unspecified, < 67.0.3396.872019-06-27
CVE-2018-6149 [HIGH] CWE-787 CVE-2018-6149: Type confusion in JavaScript in Google Chrome prior to 67.0.3396.87 allowed a remote attacker to per
Type confusion in JavaScript in Google Chrome prior to 67.0.3396.87 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2010-3116P3CRITICALCVSS 10.0fixed in 5.0.375.1272010-08-24
CVE-2010-3116 [CRITICAL] CWE-416 CVE-2010-3116: Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x be
Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to improper handling of MIME types by plug-ins.
nvd