cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 126 of 292
CVE-2026-15905P3HIGHCVSS 7.8fixed in 150.0.7871.128≥ 150.0.7871.128, < 150.0.7871.1282026-07-20
CVE-2026-15905 [HIGH] CWE-416 CVE-2026-15905: Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentia Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-13037P3HIGHCVSS 7.8fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13037 [HIGH] CWE-416 CVE-2026-13037: Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attack Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9987P3HIGHCVSS 7.8fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9987 [HIGH] CWE-20 CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 14 Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-14094P3HIGHCVSS 7.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14094 [HIGH] CWE-416 CVE-2026-14094: Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attac Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)
nvd
CVE-2026-17863P3HIGHCVSS 7.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17863 [HIGH] CWE-269 CVE-2026-17863: Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2024-9960P3HIGHCVSS 7.5fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9960 [HIGH] CWE-416 CVE-2024-9960: Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentia Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-0612P3HIGHCVSS 7.5fixed in 132.0.6834.110≥ 132.0.6834.110, < 132.0.6834.1102025-01-22
CVE-2025-0612 [HIGH] CWE-125 CVE-2025-0612: Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-21126P3MEDIUMCVSS 6.5fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21126 [MEDIUM] CWE-20 CVE-2021-21126: Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remot Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension.
nvd
CVE-2024-7017P3HIGHCVSS 7.5fixed in 126.0.6478.182≥ 126.0.6478.182, < 126.0.6478.1822025-11-14
CVE-2024-7017 [HIGH] CWE-362 CVE-2024-7017: Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote a Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8585P3HIGHCVSS 7.5fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8585 [HIGH] CWE-693 CVE-2026-8585: Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remo Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10968P3HIGHCVSS 7.4fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10968 [HIGH] CWE-20 CVE-2026-10968: Insufficient validation of untrusted input in Dawn in Google Chrome on Windows prior to 149.0.7827.5 Insufficient validation of untrusted input in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-6514P3MEDIUMCVSS 6.5fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6514 [MEDIUM] CWE-200 CVE-2020-6514: Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
nvd
CVE-2016-1645P3HIGHCVSS 8.8≤ 49.0.2623.752016-03-13
CVE-2016-1645 [HIGH] CWE-119 CVE-2016-1645: Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, a Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.
nvd
CVE-2017-5057P3HIGHCVSS 8.8fixed in 58.0.3029.81fixed in 58.0.3029.832017-10-27
CVE-2017-5057 [HIGH] CWE-843 CVE-2017-5057: Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58. Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
nvd
CVE-2016-5202P3CRITICALCVSS 9.1fixed in 54.0.2840.98fixed in 54.0.2840.99+1 more2019-10-25
CVE-2016-5202 [CRITICAL] CWE-732 CVE-2016-5202: browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 5 browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.
nvd
CVE-2018-17469P3HIGHCVSS 8.8fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672018-11-14
CVE-2018-17469 [HIGH] CWE-125 CVE-2018-17469: Incorrect handling of PDF filter chains in PDFium in Google Chrome prior to 70.0.3538.67 allowed a r Incorrect handling of PDF filter chains in PDFium in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
nvd
CVE-2021-21190P3HIGHCVSS 8.8fixed in 89.0.4389.72≥ unspecified, < 89.0.4389.722021-03-09
CVE-2021-21190 [HIGH] CWE-908 CVE-2021-21190: Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obt Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
nvd
CVE-2017-5052P3HIGHCVSS 8.8fixed in 57.0.2987.133fixed in 57.0.2987.1322017-10-27
CVE-2017-5052 [HIGH] CWE-119 CVE-2017-5052: An incorrect assumption about block structure in Blink in Google Chrome prior to 57.0.2987.133 for M An incorrect assumption about block structure in Blink in Google Chrome prior to 57.0.2987.133 for Mac, Windows, and Linux, and 57.0.2987.132 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page that triggers improper casting.
nvd
CVE-2017-5108P3HIGHCVSS 8.8fixed in 60.0.3112.782017-10-27
CVE-2017-5108 [HIGH] CWE-843 CVE-2017-5108: Type confusion in PDFium in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android Type confusion in PDFium in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted PDF file.
nvd
CVE-2017-5009P3HIGHCVSS 8.8≤ 55.0.2883.872017-02-17
CVE-2017-5009 [HIGH] CWE-119 CVE-2017-5009: WebRTC in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Andro WebRTC in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase