cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 137 of 292
CVE-2025-11207P3MEDIUMCVSS 6.5fixed in 141.0.7390.54≥ 141.0.7390.54, < 141.0.7390.542025-11-06
CVE-2025-11207 [MEDIUM] CWE-1300 CVE-2025-11207: Side-channel information leakage in Storage in Google Chrome prior to 141.0.7390.54 allowed a remote Side-channel information leakage in Storage in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-0477P4CRITICALCVSS 10.0fixed in 8.0.552.2372011-01-14
CVE-2011-0477 [CRITICAL] CWE-119 CVE-2011-0477: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle a mismatch Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle a mismatch in video frame sizes, which allows remote attackers to cause a denial of service (incorrect memory access) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2019-5849P3HIGHCVSS 8.1fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-11-25
CVE-2019-5849 [HIGH] CWE-125 CVE-2019-5849: Out of bounds read in Skia in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to obtai Out of bounds read in Skia in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2021-21134P3MEDIUMCVSS 6.5fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21134 [MEDIUM] CWE-290 CVE-2021-21134: Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote at Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2011-3919P3HIGHCVSS 7.5fixed in 16.0.912.752012-01-07
CVE-2011-3919 [HIGH] CWE-787 CVE-2011-3919: Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote at Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-1279P3HIGHCVSS 7.5≤ 43.0.2357.1342015-07-23
CVE-2015-1279 [HIGH] CWE-189 CVE-2015-1279: Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via large height and stride values.
nvd
CVE-2016-1683P3HIGHCVSS 7.5≤ 50.0.2661.1022016-06-05
CVE-2016-1683 [HIGH] CWE-119 CVE-2016-1683: numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespa numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory access) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2010-4197P3CRITICALCVSS 9.8fixed in 7.0.517.442010-11-06
CVE-2010-4197 [CRITICAL] CWE-416 CVE-2010-4197: Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text editing.
nvd
CVE-2010-4204P3CRITICALCVSS 9.8fixed in 7.0.517.442010-11-06
CVE-2010-4204 [CRITICAL] CVE-2010-4204: WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, acce WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, accesses a frame object after this object has been destroyed, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-3335P3HIGHCVSS 7.5≤ 42.0.2311.602015-04-19
CVE-2015-3335 [HIGH] CWE-264 CVE-2015-3335: The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandbox_linux/nacl_san The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandbox_linux/nacl_sandbox_linux.cc in Google Chrome before 42.0.2311.90 does not have RLIMIT_AS and RLIMIT_DATA limits for Native Client (aka NaCl) processes, which might make it easier for remote attackers to conduct row-hammer attacks or have unspecified other impact by lev
nvd
CVE-2011-3926P3HIGHCVSS 7.5fixed in 16.0.912.772012-01-24
CVE-2011-3926 [HIGH] CWE-787 CVE-2011-3926: Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote att Heap-based buffer overflow in the tree builder in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2014-1704P4CRITICALCVSS 10.0≤ 33.0.1750.146v33.0.1750.0+105 more2014-03-16
CVE-2014-1704 [CRITICAL] CVE-2014-1704: Multiple unspecified vulnerabilities in Google V8 before 3.23.17.18, as used in Google Chrome before Multiple unspecified vulnerabilities in Google V8 before 3.23.17.18, as used in Google Chrome before 33.0.1750.149, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2011-1193P3HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1193 [HIGH] CVE-2011-1193: Google V8, as used in Google Chrome before 10.0.648.127, allows remote attackers to bypass the Same Google V8, as used in Google Chrome before 10.0.648.127, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2014-3157P3HIGHCVSS 7.5≤ 35.0.1916.152v35.0.1916.0+102 more2014-06-11
CVE-2014-3157 [HIGH] CWE-119 CVE-2014-3157: Heap-based buffer overflow in the FFmpegVideoDecoder::GetVideoBuffer function in media/filters/ffmpe Heap-based buffer overflow in the FFmpegVideoDecoder::GetVideoBuffer function in media/filters/ffmpeg_video_decoder.cc in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging VideoFrame data structures that are too small for proper interaction with an underlying F
nvd
CVE-2014-3175P3CRITICALCVSS 10.0≤ 37.0.2062.93v37.0.2062.0+80 more2014-08-27
CVE-2014-3175 [CRITICAL] CVE-2014-3175: Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.94 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors, related to the load_truetype_glyph function in truetype/ttgload.c in FreeType and other functions in other components.
nvd
CVE-2015-1252P3HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-1252 [HIGH] CWE-119 CVE-2015-1252: common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wrap common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, which allows remote attackers to bypass a sandbox protection mechanism or cause a denial of service (out-of-bounds write) via vectors that trigger a write operation with a large amount of data, related to the PartialCircularBuffer::Write and PartialCir
nvd
CVE-2015-8480P4CRITICALCVSS 10.0≤ 46.0.2490.862015-12-06
CVE-2015-8480 [CRITICAL] CWE-119 CVE-2015-8480: The VideoFramePool::PoolImpl::CreateFrame function in media/base/video_frame_pool.cc in Google Chrom The VideoFramePool::PoolImpl::CreateFrame function in media/base/video_frame_pool.cc in Google Chrome before 47.0.2526.73 does not initialize memory for a video-frame data structure, which might allow remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact by leveraging improper interacti
nvd
CVE-2013-2900P3HIGHCVSS 7.5≤ 29.0.1547.56v29.0.1547.0+49 more2013-08-21
CVE-2013-2900 [HIGH] CWE-22 CVE-2013-2900: The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 o The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components composed entirely of . (dot) and whitespace characters, which allows remote attackers to conduct directory traversal attacks via a crafted directory name.
nvd
CVE-2016-5142P3CRITICALCVSS 9.8≤ 52.0.2743.822016-08-07
CVE-2016-5142 [CRITICAL] CWE-416 CVE-2016-5142: The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52 The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does not properly copy data buffers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code, related to NormalizeAlgorithm.cpp and SubtleCrypto.cpp
nvd
CVE-2013-6661P3HIGHCVSS 7.5≤ 33.0.1750.116v33.0.1750.0+95 more2014-02-24
CVE-2013-6661 [HIGH] CVE-2013-6661: Multiple unspecified vulnerabilities in Google Chrome before 33.0.1750.117 allow attackers to bypass Multiple unspecified vulnerabilities in Google Chrome before 33.0.1750.117 allow attackers to bypass the sandbox protection mechanism after obtaining renderer access, or have other impact, via unknown vectors.
nvd
Google Chrome vulnerabilities | cvebase