cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 131 of 292
CVE-2016-1656P3HIGHCVSS 7.5≤ 49.0.2623.1122016-04-18
CVE-2016-1656 [HIGH] CWE-284 CVE-2016-1656: The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unspecified vectors.
nvd
CVE-2019-13689P3HIGHCVSS 7.8fixed in 75.0.3770.80≥ 75.0.3770.80, < 75.0.3770.802023-08-25
CVE-2019-13689 [HIGH] CWE-59 CVE-2019-13689: Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remo Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical)
nvd
CVE-2026-13863P3HIGHCVSS 7.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13863 [HIGH] CWE-20 CVE-2026-13863: Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0. Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-13927P3HIGHCVSS 7.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13927 [HIGH] CWE-20 CVE-2026-13927: Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 150.0.7871.47 Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2022-1485P3HIGHCVSS 7.5fixed in 101.0.4951.41≥ unspecified, < 101.0.4951.412022-07-26
CVE-2022-1485 [HIGH] CWE-416 CVE-2022-1485: Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowed a remote attacker Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-10942P3HIGHCVSS 7.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10942 [HIGH] CWE-20 CVE-2026-10942: Inappropriate implementation in UI in Google Chrome on Windows prior to 149.0.7827.53 allowed a loca Inappropriate implementation in UI in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-7913P3HIGHCVSS 7.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7913 [HIGH] CWE-693 CVE-2026-7913: Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allow Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)
nvd
CVE-2026-7990P3HIGHCVSS 7.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7990 [HIGH] CWE-20 CVE-2026-7990: Insufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.777 Insufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2011-3045P3HIGHCVSS 8.8fixed in 17.0.963.832012-03-22
CVE-2011-3045 [HIGH] CVE-2011-3045: Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.
nvd
CVE-2020-16021P3HIGHCVSS 7.5fixed in 87.0.4280.66≥ unspecified, < 87.0.4280.662021-01-08
CVE-2020-16021 [HIGH] CWE-362 CVE-2020-16021: Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker wh Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to perform OS-level privilege escalation via a malicious file.
nvd
CVE-2010-0657P3CRITICALCVSS 9.3v0.2.149.27v0.2.149.29+44 more2010-02-18
CVE-2010-0657 [CRITICAL] CVE-2010-0657: Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quo Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut, which allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive information by tricking a user into creating a crafted shortcut.
nvd
CVE-2010-1502P3CRITICALCVSS 9.3≤ 4.1.249.1058v1.0.154.53+232 more2010-04-23
CVE-2010-1502 [CRITICAL] CVE-2010-1502: Unspecified vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to access loc Unspecified vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to access local files via vectors related to "developer tools."
nvd
CVE-2026-10976P3HIGHCVSS 7.4fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10976 [HIGH] CWE-457 CVE-2026-10976: Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtai Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2010-2296P3CRITICALCVSS 9.3fixed in 5.0.375.702010-06-15
CVE-2010-2296 [CRITICAL] CWE-264 CVE-2010-2296: The implementation of unspecified DOM methods in Google Chrome before 5.0.375.70 allows remote attac The implementation of unspecified DOM methods in Google Chrome before 5.0.375.70 allows remote attackers to bypass the Same Origin Policy via unknown vectors.
nvd
CVE-2010-4206P3HIGHCVSS 8.8fixed in 7.0.517.442010-11-06
CVE-2010-4206 [HIGH] CWE-787 CVE-2010-4206: Array index error in the FEBlend::apply function in WebCore/platform/graphics/filters/FEBlend.cpp in Array index error in the FEBlend::apply function in WebCore/platform/graphics/filters/FEBlend.cpp in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted SVG document, related to effects in the application of
nvd
CVE-2026-11115P3HIGHCVSS 7.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11115 [HIGH] CWE-416 CVE-2026-11115: Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacke Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2016-1655P3HIGHCVSS 8.8≤ 49.0.2623.1122016-04-18
CVE-2016-1655 [HIGH] CVE-2016-1655: Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during cal Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted extension.
nvd
CVE-2016-1644P3HIGHCVSS 8.8≤ 49.0.2623.752016-03-13
CVE-2016-1644 [HIGH] CVE-2016-1644: WebKit/Source/core/layout/LayoutObject.cpp in Blink, as used in Google Chrome before 49.0.2623.87, d WebKit/Source/core/layout/LayoutObject.cpp in Blink, as used in Google Chrome before 49.0.2623.87, does not properly restrict relayout scheduling, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted HTML document.
nvd
CVE-2016-1678P3HIGHCVSS 8.8≤ 50.0.2661.1022016-06-05
CVE-2016-1678 [HIGH] CWE-119 CVE-2016-1678: objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not pro objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-1681P3HIGHCVSS 8.8≤ 50.0.2661.1022016-06-05
CVE-2016-1681 [HIGH] CWE-119 CVE-2016-1681: Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
nvd
Google Chrome vulnerabilities | cvebase