Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 127 of 292
CVE-2017-5131P3HIGHCVSS 8.8fixed in 62.0.3202.622018-02-07
CVE-2017-5131 [HIGH] CWE-190 CVE-2017-5131: An integer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to pote
An integer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka an out-of-bounds write.
nvd
CVE-2017-5032P3HIGHCVSS 8.8≤ 57.0.2987.752017-04-24
CVE-2017-5032 [HIGH] CWE-787 CVE-2017-5032: PDFium in Google Chrome prior to 57.0.2987.98 for Windows could be made to increment off the end of
PDFium in Google Chrome prior to 57.0.2987.98 for Windows could be made to increment off the end of a buffer, which allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2017-5043P3HIGHCVSS 8.8≤ 57.0.2987.752017-04-24
CVE-2017-5043 [HIGH] CWE-416 CVE-2017-5043: Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free
Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.
nvd
CVE-2017-5034P3HIGHCVSS 8.8≤ 57.0.2987.752017-04-24
CVE-2017-5034 [HIGH] CWE-416 CVE-2017-5034: A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Linux and Windows allowed a re
A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
nvd
CVE-2017-5114P3HIGHCVSS 8.8fixed in 61.0.3163.79fixed in 61.0.3163.812017-10-27
CVE-2017-5114 [HIGH] CWE-119 CVE-2017-5114: Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Win
Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
nvd
CVE-2017-5080P3HIGHCVSS 8.8fixed in 59.0.3071.862017-10-27
CVE-2017-5080 [HIGH] CWE-416 CVE-2017-5080: A use after free in credit card autofill in Google Chrome prior to 59.0.3071.86 for Linux and Window
A use after free in credit card autofill in Google Chrome prior to 59.0.3071.86 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2016-1627P3HIGHCVSS 8.8≤ 48.0.2564.1032016-02-14
CVE-2016-1627 [HIGH] CWE-264 CVE-2016-1627: The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate
The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.c
nvd
CVE-2016-1622P3HIGHCVSS 8.8≤ 48.0.2564.1032016-02-14
CVE-2016-1622 [HIGH] CWE-264 CVE-2016-1622: The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.de
The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
nvd
CVE-2016-5206P3HIGHCVSS 8.8≤ 54.0.2840.992017-01-19
CVE-2016-5206 [HIGH] CWE-284 CVE-2016-5206: The PDF plugin in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 f
The PDF plugin in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly followed redirects, which allowed a remote attacker to bypass the Same Origin Policy via a crafted HTML page.
nvd
CVE-2012-4905P4MEDIUMCVSS 4.3PoC≤ 18.0.10253062012-09-13
CVE-2012-4905 [MEDIUM] CWE-79 CVE-2012-4905: Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remo
Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inject arbitrary web script or HTML via an extra in an Intent object, aka "Universal XSS (UXSS)."
nvd
CVE-2017-5113P3HIGHCVSS 8.8fixed in 61.0.3163.79fixed in 61.0.3163.812017-10-27
CVE-2017-5113 [HIGH] CWE-787 CVE-2017-5113: Math overflow in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3
Math overflow in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5111P3HIGHCVSS 8.8fixed in 61.0.3163.792017-10-27
CVE-2017-5111 [HIGH] CWE-416 CVE-2017-5111: A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowe
A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
nvd
CVE-2016-5213P3HIGHCVSS 8.8≤ 54.0.2840.992017-01-19
CVE-2016-5213 [HIGH] CWE-416 CVE-2016-5213: A use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2
A use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13741P3HIGHCVSS 8.8fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13741 [HIGH] CWE-79 CVE-2019-13741: Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a
Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.
nvd
CVE-2022-1486P3HIGHCVSS 8.8fixed in 101.0.4951.41≥ unspecified, < 101.0.4951.412022-07-26
CVE-2022-1486 [HIGH] CWE-843 CVE-2022-1486: Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to obtain pot
Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2018-6161P3HIGHCVSS 8.8fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-6161 [HIGH] CWE-20 CVE-2018-6161: Insufficient policy enforcement in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote att
Insufficient policy enforcement in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2019-13682P3HIGHCVSS 8.8fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13682 [HIGH] CWE-281 CVE-2019-13682: Insufficient policy enforcement in external protocol handling in Google Chrome prior to 77.0.3865.75
Insufficient policy enforcement in external protocol handling in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2019-13692P3HIGHCVSS 8.8fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13692 [HIGH] CWE-20 CVE-2019-13692: Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.3865.75 allowed a remo
Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.
nvd
CVE-2018-20066P3HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802019-01-09
CVE-2018-20066 [HIGH] CWE-416 CVE-2018-20066: Incorrect object lifecycle in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote att
Incorrect object lifecycle in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21202P3HIGHCVSS 8.6fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21202 [HIGH] CWE-416 CVE-2021-21202: Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convince
Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd