Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 130 of 292
CVE-2019-5854P3HIGHCVSS 8.8fixed in 76.0.3809.87≥ unspecified, < 76.0.3809.872019-11-25
CVE-2019-5854 [HIGH] CWE-190 CVE-2019-5854: Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to poten
Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2021-30506P3HIGHCVSS 8.8fixed in 90.0.4430.212≥ unspecified, < 90.0.4430.2122021-06-04
CVE-2021-30506 [HIGH] CWE-74 CVE-2021-30506: Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed
Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a web application to inject scripts or HTML into a privileged page via a crafted HTML page.
nvd
CVE-2016-10403P3HIGHCVSS 8.8fixed in 51.0.2704.63≥ unspecified, < 51.0.2704.632019-01-09
CVE-2016-10403 [HIGH] CWE-125 CVE-2016-10403: Insufficient data validation on image data in PDFium in Google Chrome prior to 51.0.2704.63 allowed
Insufficient data validation on image data in PDFium in Google Chrome prior to 51.0.2704.63 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
nvd
CVE-2014-1730P3HIGHCVSS 7.8fixed in 34.0.1847.131fixed in 34.0.1847.1322014-04-26
CVE-2014-1730 [HIGH] CWE-843 CVE-2014-1730: Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.13
Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly store internationalization metadata, which allows remote attackers to bypass intended access restrictions by leveraging "type confusion" and reading property values, related to i18n.js and runtime.cc.
nvd
CVE-2018-20065P3HIGHCVSS 8.8fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802019-01-09
CVE-2018-20065 [HIGH] CWE-20 CVE-2018-20065: Handling of URI action in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to
Handling of URI action in PDFium in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to initiate potentially unsafe navigations without a user gesture via a crafted PDF file.
nvd
CVE-2021-30593P3HIGHCVSS 8.1fixed in 92.0.4515.131≥ unspecified, < 92.0.4515.1312021-08-26
CVE-2021-30593 [HIGH] CWE-125 CVE-2021-30593: Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who conv
Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2018-6034P3HIGHCVSS 8.1fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6034 [HIGH] CWE-125 CVE-2018-6034: Insufficient data validation in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attac
Insufficient data validation in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2015-6581P3HIGHCVSS 7.5≤ 44.0.24032015-09-03
CVE-2015-6581 [HIGH] CVE-2015-6581: Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJP
Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure.
nvd
CVE-2019-8075P3HIGHCVSS 7.5fixed in 87.0.4280.66fixed in 87.0.4280.672019-09-27
CVE-2019-8075 [HIGH] CVE-2019-8075: Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerab
Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
nvd
CVE-2014-9654P3CRITICALCVSS 9.8≤ 40.0.2214.852017-04-24
CVE-2014-9654 [CRITICAL] CVE-2014-9654: The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-
The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represented in a 24-bit field, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other i
nvd
CVE-2015-1211P3HIGHCVSS 7.5fixed in 40.0.2214.109fixed in 40.0.2214.1112015-02-06
CVE-2015-1211 [HIGH] CVE-2015-1211: The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatch
The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI scheme during a ServiceWorker registration, which allows remote attackers to gain privileges via a filesystem: URI.
nvd
CVE-2018-6138P3HIGHCVSS 8.1fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-06-27
CVE-2018-6138 [HIGH] CWE-20 CVE-2018-6138: Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an
Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2015-1304P3HIGHCVSS 7.5≤ 45.0.2454.932015-10-12
CVE-2015-1304 [HIGH] CWE-284 CVE-2015-1304: object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly res
object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call.
nvd
CVE-2016-5168P3HIGHCVSS 7.5≤ 50.0.2661.912017-04-21
CVE-2016-5168 [HIGH] CWE-346 CVE-2016-5168: Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origi
Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information.
nvd
CVE-2009-3932P3CRITICALCVSS 9.3≤ 3.0.195.21v0.2.149.27+41 more2009-11-12
CVE-2009-3932 [CRITICAL] CVE-2009-3932: The Gears plugin in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a
The Gears plugin in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service (memory corruption and plugin crash) or possibly execute arbitrary code via unspecified use of the Gears SQL API, related to putting "SQL metadata into a bad state."
nvd
CVE-2014-1733P3HIGHCVSS 7.5fixed in 34.0.1847.131fixed in 34.0.1847.1322014-04-26
CVE-2014-1733 [HIGH] CWE-20 CVE-2014-1733: The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.
The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote attackers to bypass intended sandbox restrictions by leveraging renderer access.
nvd
CVE-2011-1812P3HIGHCVSS 7.5fixed in 12.0.742.912011-06-09
CVE-2011-1812 [HIGH] CVE-2011-1812: Google Chrome before 12.0.742.91 allows remote attackers to bypass intended access restrictions via
Google Chrome before 12.0.742.91 allows remote attackers to bypass intended access restrictions via vectors related to extensions.
nvd
CVE-2014-1681P3CRITICALCVSS 10.0≤ 32.0.1700.101v32.0.1700.0+67 more2014-01-28
CVE-2014-1681 [CRITICAL] CVE-2014-1681: Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.102 have unknown impact and a
Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.102 have unknown impact and attack vectors, related to 12 "security fixes [that were not] either contributed by external researchers or particularly interesting."
nvd
CVE-2021-21198P3HIGHCVSS 7.4fixed in 89.0.4389.114≥ unspecified, < 89.0.4389.1142021-04-09
CVE-2021-21198 [HIGH] CWE-125 CVE-2021-21198: Out of bounds read in IPC in Google Chrome prior to 89.0.4389.114 allowed a remote attacker who had
Out of bounds read in IPC in Google Chrome prior to 89.0.4389.114 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2015-1293P3HIGHCVSS 7.5≤ 44.0.24032015-09-03
CVE-2015-1293 [HIGH] CWE-264 CVE-2015-1293: The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attacke
The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd