Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 128 of 292
CVE-2021-21207P3HIGHCVSS 8.6fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21207 [HIGH] CWE-416 CVE-2021-21207: Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced
Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2020-16041P3HIGHCVSS 8.1fixed in 87.0.4280.88≥ unspecified, < 87.0.4280.882021-01-08
CVE-2020-16041 [HIGH] CWE-125 CVE-2020-16041: Out of bounds read in networking in Google Chrome prior to 87.0.4280.88 allowed a remote attacker wh
Out of bounds read in networking in Google Chrome prior to 87.0.4280.88 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2020-6554P3HIGHCVSS 8.6fixed in 84.0.4147.125≥ unspecified, < 84.0.4147.1252020-09-21
CVE-2020-6554 [HIGH] CWE-416 CVE-2020-6554: Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to po
Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2021-21138P3HIGHCVSS 8.6fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21138 [HIGH] CWE-416 CVE-2021-21138: Use after free in DevTools in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potent
Use after free in DevTools in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform a sandbox escape via a crafted file.
nvd
CVE-2010-1824P3CRITICALCVSS 9.3fixed in 6.0.472.592010-09-24
CVE-2010-1824 [CRITICAL] CWE-416 CVE-2010-1824: Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari
Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to SVG styles, the DOM tree, and error messages.
nvd
CVE-2016-1635P3CRITICALCVSS 9.8≤ 48.0.2564.1162016-03-06
CVE-2016-1635 [CRITICAL] CVE-2016-1635: extensions/renderer/render_frame_observer_natives.cc in Google Chrome before 49.0.2623.75 does not p
extensions/renderer/render_frame_observer_natives.cc in Google Chrome before 49.0.2623.75 does not properly consider object lifetimes and re-entrancy issues during OnDocumentElementCreated handling, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2008-6995P4MEDIUMCVSS 4.3PoCv0.2.149.272009-08-19
CVE-2008-6995 [MEDIUM] CWE-189 CVE-2008-6995: Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote atta
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid handler followed by a "%" (percent) character, which triggers a buffer over-read, as demonstrated using an "about:%" URI.
nvd
CVE-2016-5178P3CRITICALCVSS 9.8≤ 53.0.2785.1292017-05-23
CVE-2016-5178 [CRITICAL] CWE-20 CVE-2016-5178: Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-5140P3CRITICALCVSS 9.8≤ 52.0.2743.822016-08-07
CVE-2016-5140 [CRITICAL] CWE-119 CVE-2016-5140: Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in P
Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JPEG 2000 data.
nvd
CVE-2018-6176P3HIGHCVSS 7.8fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-6176 [HIGH] CWE-20 CVE-2018-6176: Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed
Insufficient file type enforcement in Extensions API in Google Chrome prior to 68.0.3440.75 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted Chrome Extension.
nvd
CVE-2023-2135P3HIGHCVSS 7.5fixed in 112.0.5615.137≥ 112.0.5615.137, < 112.0.5615.1372023-04-19
CVE-2023-2135 [HIGH] CWE-416 CVE-2023-2135: Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who co
Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13800P3HIGHCVSS 7.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13800 [HIGH] CWE-284 CVE-2026-13800: Inappropriate implementation in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a
Inappropriate implementation in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-13827P3HIGHCVSS 7.8fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13827 [HIGH] CWE-416 CVE-2026-13827: Use after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to
Use after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-14060P3HIGHCVSS 7.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14060 [HIGH] CWE-20 CVE-2026-14060: Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.
Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)
nvd
CVE-2026-7925P3HIGHCVSS 7.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7925 [HIGH] CWE-416 CVE-2026-7925: Use after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local atta
Use after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-14018P3HIGHCVSS 7.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14018 [HIGH] CWE-416 CVE-2026-14018: Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacke
Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-7994P3HIGHCVSS 7.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7994 [HIGH] CWE-269 CVE-2026-7994: Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowe
Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-11072P3HIGHCVSS 7.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11072 [HIGH] CWE-416 CVE-2026-11072: Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacke
Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-14124P3HIGHCVSS 7.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14124 [HIGH] CWE-269 CVE-2026-14124: Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.4
Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)
nvd
CVE-2026-11103P3HIGHCVSS 7.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11103 [HIGH] CWE-269 CVE-2026-11103: Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed
Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd