Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 135 of 292
CVE-2012-5142P3CRITICALCVSS 10.0≤ 23.0.1271.96v23.0.1271.0+66 more2012-12-12
CVE-2012-5142 [CRITICAL] CWE-94 CVE-2012-5142: Google Chrome before 23.0.1271.97 does not properly handle history navigation, which allows remote a
Google Chrome before 23.0.1271.97 does not properly handle history navigation, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2021-21130P3MEDIUMCVSS 6.5fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21130 [MEDIUM] CVE-2021-21130: Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
nvd
CVE-2021-21129P3MEDIUMCVSS 6.5fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21129 [MEDIUM] CVE-2021-21129: Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
nvd
CVE-2021-21141P3MEDIUMCVSS 6.5fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21141 [MEDIUM] CWE-74 CVE-2021-21141: Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy via a crafted HTML page.
nvd
CVE-2011-3099P3CRITICALCVSS 10.0≤ 19.0.1084.452012-05-16
CVE-2011-3099 [CRITICAL] CWE-399 CVE-2011-3099: Use-after-free vulnerability in the PDF functionality in Google Chrome before 19.0.1084.46 allows re
Use-after-free vulnerability in the PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a malformed name for the font encoding.
nvd
CVE-2011-3091P3CRITICALCVSS 10.0≤ 19.0.1084.452012-05-16
CVE-2011-3091 [CRITICAL] CWE-399 CVE-2011-3091: Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 19.0.1084.46 al
Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2020-6510P3HIGHCVSS 7.8fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6510 [HIGH] CWE-787 CVE-2020-6510: Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote att
Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2015-6755P3HIGHCVSS 7.5≤ 45.0.2454.1012015-10-15
CVE-2015-6755 [HIGH] CWE-264 CVE-2015-6755: The ContainerNode::parserInsertBefore function in core/dom/ContainerNode.cpp in Blink, as used in Go
The ContainerNode::parserInsertBefore function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 46.0.2490.71, proceeds with a DOM tree insertion in certain cases where a parent node no longer contains a child node, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
nvd
CVE-2015-1274P3MEDIUMCVSS 6.8≤ 43.0.2357.1342015-07-23
CVE-2015-1274 [MEDIUM] CWE-254 CVE-2015-1274: Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file t
Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user's previous "Always open files of this type" choice, related to download_commands.cc and download_prefs.cc.
nvd
CVE-2015-1302P3HIGHCVSS 7.5≤ 46.0.2490.802015-11-11
CVE-2015-1302 [HIGH] CWE-20 CVE-2015-1302: The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages an
The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages and API exposure, which allows remote attackers to bypass the Same Origin Policy via an unintended embedder or unintended plugin loading, related to pdf.js and out_of_process_instance.cc.
nvd
CVE-2010-0658P3CRITICALCVSS 9.3≤ 4.0.249.0v0.2.149.27+46 more2010-02-18
CVE-2010-0658 [CRITICAL] CWE-189 CVE-2010-0658: Multiple integer overflows in Skia, as used in Google Chrome before 4.0.249.78, allow remote attacke
Multiple integer overflows in Skia, as used in Google Chrome before 4.0.249.78, allow remote attackers to execute arbitrary code in the Chrome sandbox or cause a denial of service (memory corruption and application crash) via vectors involving CANVAS elements.
nvd
CVE-2021-37969P3HIGHCVSS 7.8fixed in 94.0.4606.54≥ unspecified, < 94.0.4606.542021-10-08
CVE-2021-37969 [HIGH] CWE-59 CVE-2021-37969: Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 all
Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.
nvd
CVE-2009-1514P4MEDIUMCVSS 5.0PoCv1.0.154.532009-05-04
CVE-2009-1514 [MEDIUM] CWE-399 CVE-2009-1514: Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer derefere
Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement with a long exception value.
nvd
CVE-2016-5141P3HIGHCVSS 7.5≤ 52.0.2743.822016-08-07
CVE-2016-5141 [HIGH] CWE-20 CVE-2016-5141: Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address b
Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address bar via vectors involving a provisional URL for an initially empty document, related to FrameLoader.cpp and ScopedPageLoadDeferrer.cpp.
nvd
CVE-2011-2332P3HIGHCVSS 7.5fixed in 12.0.742.912011-06-09
CVE-2011-2332 [HIGH] CWE-20 CVE-2011-2332: Google V8, as used in Google Chrome before 12.0.742.91, allows remote attackers to bypass the Same O
Google V8, as used in Google Chrome before 12.0.742.91, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2016-1642P3CRITICALCVSS 9.8≤ 48.0.2564.1162016-03-06
CVE-2016-1642 [CRITICAL] CVE-2016-1642: Multiple unspecified vulnerabilities in Google Chrome before 49.0.2623.75 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 49.0.2623.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2013-0831P3HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0831 [HIGH] CWE-22 CVE-2013-0831: Directory traversal vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to ha
Directory traversal vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to have an unspecified impact by leveraging access to an extension process.
nvd
CVE-2016-1659P3CRITICALCVSS 9.8≤ 49.0.2623.1122016-04-18
CVE-2016-1659 [CRITICAL] CVE-2016-1659: Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2008-4340P4MEDIUMCVSS 4.3PoCv0.2.149.29v0.2.149.302008-09-30
CVE-2008-4340 [MEDIUM] CWE-20 CVE-2008-4340: Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attackers to cause a denial of service (memory
Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attackers to cause a denial of service (memory consumption) via an HTML document containing a carriage return ("\r\n\r\n") argument to the window.open function.
nvd
CVE-2016-1666P3CRITICALCVSS 9.8≤ 50.0.2661.872016-05-14
CVE-2016-1666 [CRITICAL] CVE-2016-1666: Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd