Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 138 of 292
CVE-2011-1438P3HIGHCVSS 7.5fixed in 11.0.696.572011-05-03
CVE-2011-1438 [HIGH] CWE-20 CVE-2011-1438: Google Chrome before 11.0.696.57 allows remote attackers to bypass the Same Origin Policy via vector
Google Chrome before 11.0.696.57 allows remote attackers to bypass the Same Origin Policy via vectors involving blobs.
nvd
CVE-2010-2297P3CRITICALCVSS 9.3fixed in 5.0.375.702010-06-15
CVE-2010-2297 [CRITICAL] CWE-94 CVE-2010-2297: rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote
rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that has a large colspan attribute within a table.
nvd
CVE-2018-17470P3HIGHCVSS 7.4fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672019-01-09
CVE-2018-17470 [HIGH] CWE-119 CVE-2018-17470: A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who h
A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2010-1234P3HIGHCVSS 7.5≤ 4.1.249.1035v0.1.38.1+221 more2010-04-01
CVE-2010-1234 [HIGH] CVE-2010-1234: Unspecified vulnerability in Google Chrome before 4.1.249.1036 allows remote attackers to truncate t
Unspecified vulnerability in Google Chrome before 4.1.249.1036 allows remote attackers to truncate the URL shown in the HTTP Basic Authentication dialog via unknown vectors.
nvd
CVE-2019-5780P3HIGHCVSS 7.8fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5780 [HIGH] CWE-20 CVE-2019-5780: Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 7
Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.
nvd
CVE-2020-15980P3HIGHCVSS 7.8fixed in 86.0.4240.75≥ unspecified, < 86.0.4240.752020-11-03
CVE-2020-15980 [HIGH] CVE-2020-15980: Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed a local attacker to bypass navigation restrictions via crafted Intents.
nvd
CVE-2021-21117P3HIGHCVSS 7.8fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21117 [HIGH] CWE-59 CVE-2021-21117: Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local
Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local attacker to perform OS-level privilege escalation via a crafted file.
nvd
CVE-2020-6546P3HIGHCVSS 7.8fixed in 84.0.4147.125≥ unspecified, < 84.0.4147.1252020-09-21
CVE-2020-6546 [HIGH] CWE-59 CVE-2020-6546: Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local at
Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
nvd
CVE-2016-2843P3CRITICALCVSS 9.8≤ 48.0.2564.1162016-03-06
CVE-2016-2843 [CRITICAL] CVE-2016-2843: Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before 49.0.2623.75, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2009-3931P3CRITICALCVSS 9.3≤ 3.0.195.21v0.2.149.27+41 more2009-11-12
CVE-2009-3931 [CRITICAL] CWE-20 CVE-2009-3931: Incomplete blacklist vulnerability in browser/download/download_exe.cc in Google Chrome before 3.0.1
Incomplete blacklist vulnerability in browser/download/download_exe.cc in Google Chrome before 3.0.195.32 allows remote attackers to force the download of certain dangerous files via a "Content-Disposition: attachment" designation, as demonstrated by (1) .mht and (2) .mhtml files, which are automatically executed by Internet Explorer 6; (3) .svg file
nvd
CVE-2016-2051P4CRITICALCVSS 9.8≤ 47.0.2526.1112016-01-25
CVE-2016-2051 [CRITICAL] CVE-2016-2051: Multiple unspecified vulnerabilities in Google V8 before 4.8.271.17, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.8.271.17, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2008-6997P4MEDIUMCVSS 4.3PoCv0.2.149.272009-08-19
CVE-2008-6997 [MEDIUM] CVE-2008-6997: Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser
Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser crash) via an IMG tag with a long src attribute, which triggers the crash when the victim performs an "Inspect Element" action.
nvd
CVE-2009-2121P3CRITICALCVSS 9.3≤ 2.0.172v0.2.149.29+22 more2009-06-23
CVE-2009-2121 [CRITICAL] CWE-119 CVE-2009-2121: Buffer overflow in the browser kernel in Google Chrome before 2.0.172.33 allows remote HTTP servers
Buffer overflow in the browser kernel in Google Chrome before 2.0.172.33 allows remote HTTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted response.
nvd
CVE-2021-4098P3HIGHCVSS 7.4fixed in 96.0.4664.110≥ unspecified, < 96.0.4664.1102022-02-11
CVE-2021-4098 [HIGH] CWE-367 CVE-2021-4098: Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attack
Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2017-15403P3HIGHCVSS 7.3fixed in 61.0.3163.113≥ unspecified, < 61.0.3163.1132019-01-09
CVE-2017-15403 [HIGH] CWE-77 CVE-2017-15403: Insufficient data validation in crosh could lead to a command injection under chronos privileges in
Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2016-1653P4HIGHCVSS 8.8≤ 49.0.2623.1122016-04-18
CVE-2016-1653 [HIGH] CWE-119 CVE-2016-1653: The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles
The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds write operation, related to compiler/pipeline.cc and compiler/simplified-lowering.
nvd
CVE-2013-6668P3HIGHCVSS 7.5≤ 33.0.1750.144v33.0.1750.0+104 more2014-03-05
CVE-2013-6668 [HIGH] CVE-2013-6668: Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-2844P4HIGHCVSS 8.8≤ 48.0.2564.1162016-03-06
CVE-2016-2844 [HIGH] CWE-20 CVE-2016-2844: WebKit/Source/core/layout/LayoutBlock.cpp in Blink, as used in Google Chrome before 49.0.2623.75, do
WebKit/Source/core/layout/LayoutBlock.cpp in Blink, as used in Google Chrome before 49.0.2623.75, does not properly determine when anonymous block wrappers may exist, which allows remote attackers to cause a denial of service (incorrect cast and assertion failure) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-5129P4HIGHCVSS 8.8v51.0.2704.1062016-07-23
CVE-2016-5129 [HIGH] CWE-119 CVE-2016-5129: Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process
Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2026-11269P3HIGHCVSS 7.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11269 [HIGH] CWE-829 CVE-2026-11269: Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attack
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)
nvd