Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 132 of 292
CVE-2017-5063P3HIGHCVSS 8.8fixed in 58.0.3029.81fixed in 58.0.3029.832017-10-27
CVE-2017-5063 [HIGH] CWE-190 CVE-2017-5063: A numeric overflow in Skia in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 5
A numeric overflow in Skia in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2016-1709P3HIGHCVSS 8.8≤ 51.0.2704.1062016-07-23
CVE-2016-1709 [HIGH] CWE-119 CVE-2016-1709: Heap-based buffer overflow in the ByteArray::Get method in data/byte_array.cc in Google sfntly befor
Heap-based buffer overflow in the ByteArray::Get method in data/byte_array.cc in Google sfntly before 2016-06-10, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SFNT font.
nvd
CVE-2016-5145P3HIGHCVSS 8.8≤ 52.0.2743.822016-08-07
CVE-2016-5145 [HIGH] CWE-254 CVE-2016-5145: Blink, as used in Google Chrome before 52.0.2743.116, does not ensure that a taint property is prese
Blink, as used in Google Chrome before 52.0.2743.116, does not ensure that a taint property is preserved after a structure-clone operation on an ImageBitmap object derived from a cross-origin image, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
nvd
CVE-2016-5128P3HIGHCVSS 8.8≤ 51.0.2704.1062016-07-23
CVE-2016-5128 [HIGH] CWE-254 CVE-2016-5128: objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not pr
objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API interceptors from modifying a store target without setting a property, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2016-1668P3HIGHCVSS 8.8≤ 50.0.2661.872016-05-14
CVE-2016-1668 [HIGH] CWE-284 CVE-2016-1668: The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Bl
The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2018-6151P3HIGHCVSS 8.8fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6151 [HIGH] CWE-125 CVE-2018-6151: Bad cast in DevTools in Google Chrome on Win, Linux, Mac, Chrome OS prior to 66.0.3359.117 allowed a
Bad cast in DevTools in Google Chrome on Win, Linux, Mac, Chrome OS prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension.
nvd
CVE-2026-11218P3MEDIUMCVSS 6.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11218 [MEDIUM] CWE-20 CVE-2026-11218: Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.
Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a malicious file. (Chromium security severity: Low)
nvd
CVE-2016-1623P3HIGHCVSS 8.8≤ 48.0.2564.1032016-02-14
CVE-2016-1623 [HIGH] CWE-264 CVE-2016-1623: The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach
The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-detach operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to FrameLoader.cpp, HTMLFrameOwnerElement.h, LocalFrame.cpp, and WebLocalFrameImpl.cpp.
nvd
CVE-2016-5138P3HIGHCVSS 8.8≤ 52.0.2743.822016-08-01
CVE-2016-5138 [HIGH] CWE-190 CVE-2016-5138: Integer overflow in the kbasep_vinstr_attach_client function in midgard/mali_kbase_vinstr.c in Googl
Integer overflow in the kbasep_vinstr_attach_client function in midgard/mali_kbase_vinstr.c in Google Chrome before 52.0.2743.85 allows remote attackers to cause a denial of service (heap-based buffer overflow and use-after-free) by leveraging an unrestricted multiplication.
nvd
CVE-2016-5183P3HIGHCVSS 8.8≤ 53.0.2785.1432016-12-18
CVE-2016-5183 [HIGH] CWE-416 CVE-2016-5183: A heap use after free in PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux;
A heap use after free in PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android allows a remote attacker to potentially exploit heap corruption via crafted PDF files.
nvd
CVE-2016-5211P3HIGHCVSS 8.8≤ 54.0.2840.992017-01-19
CVE-2016-5211 [HIGH] CWE-416 CVE-2016-5211: A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55
A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2016-5203P3HIGHCVSS 8.8≤ 54.0.2840.992017-01-19
CVE-2016-5203 [HIGH] CWE-416 CVE-2016-5203: A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55
A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2017-15406P3HIGHCVSS 8.8fixed in 62.0.3202.752018-08-28
CVE-2017-15406 [HIGH] CWE-119 CVE-2017-15406: A stack buffer overflow in V8 in Google Chrome prior to 62.0.3202.75 allowed a remote attacker to pe
A stack buffer overflow in V8 in Google Chrome prior to 62.0.3202.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2011-3086P3CRITICALCVSS 10.0≤ 19.0.1084.452012-05-16
CVE-2011-3086 [CRITICAL] CWE-399 CVE-2011-3086: Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a STYLE element.
nvd
CVE-2015-6788P3CRITICALCVSS 10.0≤ 47.0.2526.732015-12-14
CVE-2015-6788 [CRITICAL] CVE-2015-6788: The ObjectBackedNativeHandler class in extensions/renderer/object_backed_native_handler.cc in the ex
The ObjectBackedNativeHandler class in extensions/renderer/object_backed_native_handler.cc in the extensions subsystem in Google Chrome before 47.0.2526.80 improperly implements handler functions, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
nvd
CVE-2011-3089P3CRITICALCVSS 10.0≤ 19.0.1084.452012-05-16
CVE-2011-3089 [CRITICAL] CWE-399 CVE-2011-3089: Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables.
nvd
CVE-2012-5137P3CRITICALCVSS 10.0≤ 23.0.1271.94v23.0.1271.0+64 more2012-12-04
CVE-2012-5137 [CRITICAL] CWE-416 CVE-2012-5137: Use-after-free vulnerability in Google Chrome before 23.0.1271.95 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 23.0.1271.95 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the Media Source API.
nvd
CVE-2021-30536P3HIGHCVSS 8.1fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30536 [HIGH] CWE-125 CVE-2021-30536: Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potenti
Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.
nvd
CVE-2012-5134P3MEDIUMCVSS 6.8≤ 23.0.1271.89v23.0.1271.0+58 more2012-11-28
CVE-2012-5134 [MEDIUM] CWE-119 CVE-2012-5134: Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and
Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.
nvd
CVE-2020-6555P3HIGHCVSS 7.6fixed in 84.0.4147.125≥ unspecified, < 84.0.4147.1252020-09-21
CVE-2020-6555 [HIGH] CWE-125 CVE-2020-6555: Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obt
Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd