Google Chrome vulnerabilities

4,008 known vulnerabilities affecting google/chrome.

Total CVEs
4,008
CISA KEV
74
actively exploited
Public exploits
63
Exploited in wild
65
Severity breakdown
CRITICAL298HIGH2025MEDIUM1626LOW17UNKNOWN42

Vulnerabilities

Page 126 of 201
CVE-2017-5095HIGHCVSS 8.8≤ 60.0.3112.782017-10-27
CVE-2017-5095 [HIGH] CWE-787 CVE-2017-5095: Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack corruption via a crafted PDF file.
nvd
CVE-2017-5112HIGHCVSS 8.8fixed in 61.0.3163.792017-10-27
CVE-2017-5112 [HIGH] CWE-119 CVE-2017-5112: Heap buffer overflow in WebGL in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote at Heap buffer overflow in WebGL in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2017-5087HIGHCVSS 8.8fixed in 59.0.3071.104fixed in 59.0.3071.1172017-10-27
CVE-2017-5087 [HIGH] CWE-416 CVE-2017-5087: A use after free in Blink in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 5 A use after free in Blink in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, aka an IndexedDB sandbox escape.
nvd
CVE-2017-5100HIGHCVSS 8.8≤ 60.0.3112.782017-10-27
CVE-2017-5100 [HIGH] CWE-416 CVE-2017-5100: A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacke A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-5114HIGHCVSS 8.8fixed in 61.0.3163.79fixed in 61.0.3163.812017-10-27
CVE-2017-5114 [HIGH] CWE-119 CVE-2017-5114: Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Win Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
nvd
CVE-2017-5078HIGHCVSS 8.8fixed in 59.0.3071.862017-10-27
CVE-2017-5078 [HIGH] CVE-2017-5078: Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59. Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac allowed a remote attacker to perform command injection via a crafted HTML page, a similar issue to CVE-2004-0121. For example, characters such as * have an incorrect interaction with xdg-email in xdg-utils, and a space charac
nvd
CVE-2017-5115HIGHCVSS 8.8fixed in 61.0.3163.792017-10-27
CVE-2017-5115 [HIGH] CWE-704 CVE-2017-5115: Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
nvd
CVE-2017-5064HIGHCVSS 8.8fixed in 58.0.3029.812017-10-27
CVE-2017-5064 [HIGH] CWE-119 CVE-2017-5064: Incorrect handling of DOM changes in Blink in Google Chrome prior to 58.0.3029.81 for Windows allowe Incorrect handling of DOM changes in Blink in Google Chrome prior to 58.0.3029.81 for Windows allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5068HIGHCVSS 7.5fixed in 58.0.3029.962017-10-27
CVE-2017-5068 [HIGH] CWE-362 CVE-2017-5068: Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page.
nvd
CVE-2017-5074HIGHCVSS 8.0fixed in 59.0.3071.862017-10-27
CVE-2017-5074 [HIGH] CWE-416 CVE-2017-5074: A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, related to Bluetooth.
nvd
CVE-2017-5062HIGHCVSS 8.8fixed in 58.0.3029.81fixed in 58.0.3029.832017-10-27
CVE-2017-5062 [HIGH] CWE-416 CVE-2017-5062: A use after free in Chrome Apps in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, A use after free in Chrome Apps in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to potentially perform out of bounds memory access via a crafted Chrome extension.
nvd
CVE-2017-5070HIGHCVSS 8.8KEVfixed in 59.0.3071.86fixed in 59.0.3071.922017-10-27
CVE-2017-5070 [HIGH] CWE-843 CVE-2017-5070: Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.30 Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2017-5099HIGHCVSS 8.8≤ 60.0.3112.762017-10-27
CVE-2017-5099 [HIGH] CWE-20 CVE-2017-5099: Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 f Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to potentially gain privilege elevation via a crafted HTML page.
nvd
CVE-2017-5116HIGHCVSS 8.8fixed in 61.0.3163.79fixed in 61.0.3163.812017-10-27
CVE-2017-5116 [HIGH] CWE-843 CVE-2017-5116: Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.31 Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2017-5054HIGHCVSS 8.8fixed in 57.0.2987.133fixed in 57.0.2987.1322017-10-27
CVE-2017-5054 [HIGH] CWE-125 CVE-2017-5054: An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to obtain heap memory contents via a crafted HTML page.
nvd
CVE-2017-5111HIGHCVSS 8.8fixed in 61.0.3163.792017-10-27
CVE-2017-5111 [HIGH] CWE-416 CVE-2017-5111: A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowe A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
nvd
CVE-2017-5059HIGHCVSS 8.8fixed in 58.0.3029.81fixed in 58.0.3029.832017-10-27
CVE-2017-5059 [HIGH] CWE-843 CVE-2017-5059: Type confusion in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0 Type confusion in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to potentially obtain code execution via a crafted HTML page.
nvd
CVE-2017-5063HIGHCVSS 8.8fixed in 58.0.3029.81fixed in 58.0.3029.832017-10-27
CVE-2017-5063 [HIGH] CWE-190 CVE-2017-5063: A numeric overflow in Skia in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 5 A numeric overflow in Skia in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-5088HIGHCVSS 8.8fixed in 59.0.3071.104fixed in 59.0.3071.1172017-10-27
CVE-2017-5088 [HIGH] CWE-125 CVE-2017-5088: Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.104 for Mac, Wi Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2017-5073HIGHCVSS 8.8fixed in 59.0.3071.86fixed in 59.0.3071.922017-10-27
CVE-2017-5073 [HIGH] CWE-416 CVE-2017-5073: Use after free in print preview in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, Use after free in print preview in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd