Google Chrome vulnerabilities
4,008 known vulnerabilities affecting google/chrome.
Total CVEs
4,008
CISA KEV
74
actively exploited
Public exploits
63
Exploited in wild
65
Severity breakdown
CRITICAL298HIGH2025MEDIUM1626LOW17UNKNOWN42
Vulnerabilities
Page 128 of 201
CVE-2017-5085MEDIUMCVSS 6.1v58.0.30292017-10-27
CVE-2017-5085 [MEDIUM] CWE-79 CVE-2017-5085: Inappropriate implementation in Bookmarks in Google Chrome prior to 59 for iOS allowed a remote atta
Inappropriate implementation in Bookmarks in Google Chrome prior to 59 for iOS allowed a remote attacker who convinced the user to perform certain operations to run JavaScript on chrome:// pages via a crafted bookmark.
nvd
CVE-2017-5082MEDIUMCVSS 5.5fixed in 59.0.3071.922017-10-27
CVE-2017-5082 [MEDIUM] CWE-200 CVE-2017-5082: Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to
Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacker to take screen shots of credit card information via a crafted HTML page.
nvd
CVE-2017-5120MEDIUMCVSS 6.5fixed in 61.0.3163.79fixed in 61.0.3163.812017-10-27
CVE-2017-5120 [MEDIUM] CVE-2017-5120: Inappropriate use of www mismatch redirects in browser navigation in Google Chrome prior to 61.0.316
Inappropriate use of www mismatch redirects in browser navigation in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially downgrade HTTPS requests to HTTP via a crafted HTML page. In other words, Chrome could transmit cleartext even though the user had entered an https URL, bec
nvd
CVE-2017-5060MEDIUMCVSS 6.5fixed in 58.0.3029.81fixed in 58.0.3029.832017-10-27
CVE-2017-5060 [MEDIUM] CWE-863 CVE-2017-5060: Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac, Windows,
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
nvd
CVE-2017-5106MEDIUMCVSS 6.5≤ 60.0.3112.782017-10-27
CVE-2017-5106 [MEDIUM] CWE-20 CVE-2017-5106: Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows,
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
nvd
CVE-2017-5061MEDIUMCVSS 5.3fixed in 58.0.3029.812017-10-27
CVE-2017-5061 [MEDIUM] CWE-362 CVE-2017-5061: A race condition in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac al
A race condition in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2017-5076MEDIUMCVSS 6.5fixed in 59.0.3071.86fixed in 59.0.3071.922017-10-27
CVE-2017-5076 [MEDIUM] CWE-20 CVE-2017-5076: Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Mac, Windows,
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
nvd
CVE-2017-5083MEDIUMCVSS 4.3fixed in 59.0.3071.86fixed in 59.0.3071.922017-10-27
CVE-2017-5083 [MEDIUM] CWE-20 CVE-2017-5083: Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and L
Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.
nvd
CVE-2017-5066MEDIUMCVSS 6.5fixed in 58.0.3029.81fixed in 58.0.3029.832017-10-27
CVE-2017-5066 [MEDIUM] CWE-347 CVE-2017-5066: Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior
Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to incorrectly accept a badly formed X.509 certificate via a crafted HTML page.
nvd
CVE-2017-5072MEDIUMCVSS 6.5fixed in 59.0.3071.922017-10-27
CVE-2017-5072 [MEDIUM] CWE-20 CVE-2017-5072: Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a
Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with RTL characters via a crafted URL page.
nvd
CVE-2017-5101MEDIUMCVSS 6.5≤ 60.0.3112.782017-10-27
CVE-2017-5101 [MEDIUM] CVE-2017-5101: Inappropriate implementation in Omnibox in Google Chrome prior to 60.0.3112.78 for Linux, Windows, a
Inappropriate implementation in Omnibox in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
nvd
CVE-2017-5079MEDIUMCVSS 4.3fixed in 59.0.3071.86fixed in 59.0.3071.922017-10-27
CVE-2017-5079 [MEDIUM] CWE-20 CVE-2017-5079: Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and L
Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.
nvd
CVE-2017-5069MEDIUMCVSS 6.1fixed in 58.0.3029.81fixed in 58.0.3029.832017-10-27
CVE-2017-5069 [MEDIUM] CWE-79 CVE-2017-5069: Incorrect MIME type of XSS-Protection reports in Blink in Google Chrome prior to 58.0.3029.81 for Li
Incorrect MIME type of XSS-Protection reports in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to circumvent Cross-Origin Resource Sharing checks via a crafted HTML page.
nvd
CVE-2017-5107MEDIUMCVSS 5.3fixed in 60.0.3112.782017-10-27
CVE-2017-5107 [MEDIUM] CWE-203 CVE-2017-5107: A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac
A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a crafted HTML page.
nvd
CVE-2017-5093MEDIUMCVSS 6.5fixed in 60.0.3112.782017-10-27
CVE-2017-5093 [MEDIUM] CWE-20 CVE-2017-5093: Inappropriate implementation in modal dialog handling in Blink in Google Chrome prior to 60.0.3112.7
Inappropriate implementation in modal dialog handling in Blink in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to prevent a full screen warning from being displayed via a crafted HTML page.
nvd
CVE-2017-5090MEDIUMCVSS 6.5fixed in 59.0.3071.1152017-10-27
CVE-2017-5090 [MEDIUM] CWE-20 CVE-2017-5090: Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.115 for Mac allowed a
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.115 for Mac allowed a remote attacker to perform domain spoofing via a crafted domain name containing a U+0620 character, aka Apple rdar problem 32458012.
nvd
CVE-2017-5104MEDIUMCVSS 6.5≤ 60.0.3112.782017-10-27
CVE-2017-5104 [MEDIUM] CWE-20 CVE-2017-5104: Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed
Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to spoof the contents of the omnibox via a crafted HTML page.
nvd
CVE-2017-5086MEDIUMCVSS 6.5fixed in 59.0.3071.862017-10-27
CVE-2017-5086 [MEDIUM] CWE-20 CVE-2017-5086: Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Windows and Ma
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Windows and Mac allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
nvd
CVE-2017-5075MEDIUMCVSS 4.3fixed in 59.0.3071.86fixed in 59.0.3071.922017-10-27
CVE-2017-5075 [MEDIUM] CWE-200 CVE-2017-5075: Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Li
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.
nvd
CVE-2017-5119MEDIUMCVSS 4.3fixed in 61.0.3163.1002017-10-27
CVE-2017-5119 [MEDIUM] CWE-119 CVE-2017-5119: Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and L
Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd