Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 139 of 292
CVE-2016-5136P3HIGHCVSS 8.8≤ 51.0.2704.1062016-07-23
CVE-2016-5136 [HIGH] CWE-416 CVE-2016-5136: Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsys
Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome before 52.0.2743.82 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to script deletion.
nvd
CVE-2016-5167P3HIGHCVSS 8.8≤ 52.0.2743.1162016-09-11
CVE-2016-5167 [HIGH] CVE-2016-5167: Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.89 on Windows and OS X and be
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-1620P4HIGHCVSS 8.8≤ 47.0.2526.1062016-01-25
CVE-2016-1620 [HIGH] CVE-2016-1620: Multiple unspecified vulnerabilities in Google Chrome before 48.0.2564.82 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 48.0.2564.82 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-1680P3HIGHCVSS 8.8≤ 50.0.2661.1022016-06-05
CVE-2016-1680 [HIGH] CWE-119 CVE-2016-1680: Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome befo
Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2016-3679P4HIGHCVSS 8.8≤ 49.0.2623.952016-03-29
CVE-2016-3679 [HIGH] CVE-2016-3679: Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2026-5893P3MEDIUMCVSS 6.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5893 [MEDIUM] CWE-362 CVE-2026-5893: Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit
Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2016-5170P3HIGHCVSS 8.8≤ 53.0.2785.1012016-09-25
CVE-2016-5170 [HIGH] CWE-416 CVE-2016-5170: WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not properly consider getter side effects during array key conversion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted Indexed Database (aka IndexedDB) AP
nvd
CVE-2016-7549P3HIGHCVSS 8.8≤ 53.0.2785.1012016-09-25
CVE-2016-7549 [HIGH] CVE-2016-7549: Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a
Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or possibly have unspecified other impact by leveraging access to a renderer process, related to render_frame_host_imp
nvd
CVE-2021-4324P3MEDIUMCVSS 6.5fixed in 90.0.4430.93≥ 90.0.4430.93, < 90.0.4430.932023-07-29
CVE-2021-4324 [MEDIUM] CVE-2021-4324: Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a re
Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to read arbitrary files via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-17679P3MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17679 [MEDIUM] CWE-20 CVE-2026-17679: Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72
Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10981P3MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10981 [MEDIUM] CWE-20 CVE-2026-10981: Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted video file. (Chromium security severity: High)
nvd
CVE-2012-5144P4CRITICALCVSS 10.0≤ 23.0.1271.96v23.0.1271.0+66 more2012-12-12
CVE-2012-5144 [CRITICAL] CWE-119 CVE-2012-5144: Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not prope
Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via vectors related to "an off-by-one overwrite when switching to LTP profile from MAIN."
nvd
CVE-2026-17789P3MEDIUMCVSS 6.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17789 [MEDIUM] CWE-20 CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Medium)
nvd
CVE-2026-17923P3MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17923 [MEDIUM] CWE-693 CVE-2026-17923: Policy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to byp
Policy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted domain name. (Chromium security severity: Low)
nvd
CVE-2026-17929P3MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17929 [MEDIUM] CWE-20 CVE-2026-17929: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allow
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)
nvd
CVE-2010-3113P4CRITICALCVSS 10.0fixed in 5.0.375.1272010-08-24
CVE-2010-3113 [CRITICAL] CWE-119 CVE-2010-3113: Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents
Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors related to state changes when using DeleteButtonController.
nvd
CVE-2011-0982P4CRITICALCVSS 10.0fixed in 9.0.597.942011-02-10
CVE-2011-0982 [CRITICAL] CWE-416 CVE-2011-0982: Use-after-free vulnerability in Google Chrome before 9.0.597.94 allows remote attackers to cause a d
Use-after-free vulnerability in Google Chrome before 9.0.597.94 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG font faces.
nvd
CVE-2011-0478P4CRITICALCVSS 10.0fixed in 8.0.552.2372011-01-14
CVE-2011-0478 [CRITICAL] CWE-20 CVE-2011-0478: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle SVG use ele
Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle SVG use elements, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2016-1651P3HIGHCVSS 8.1≤ 49.0.2623.1122016-04-18
CVE-2016-1651 [HIGH] CWE-200 CVE-2016-1651: fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via crafted JPEG 2000 data in a PDF document.
nvd
CVE-2011-3092P4CRITICALCVSS 10.0≤ 19.0.1084.452012-05-16
CVE-2011-3092 [CRITICAL] CWE-20 CVE-2011-3092: The regex implementation in Google V8, as used in Google Chrome before 19.0.1084.46, allows remote a
The regex implementation in Google V8, as used in Google Chrome before 19.0.1084.46, allows remote attackers to cause a denial of service (invalid write operation) or possibly have unspecified other impact via unknown vectors.
nvd