Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 141 of 292
CVE-2011-0481P4CRITICALCVSS 9.3fixed in 8.0.552.2372011-01-14
CVE-2011-0481 [CRITICAL] CWE-120 CVE-2011-0481: Buffer overflow in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote a
Buffer overflow in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to PDF shading.
nvd
CVE-2011-2825P4CRITICALCVSS 9.3fixed in 13.0.782.2152011-08-29
CVE-2011-2825 [CRITICAL] CWE-416 CVE-2011-2825: Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving custom fonts.
nvd
CVE-2009-1441P4CRITICALCVSS 9.3≤ 1.0.154.53v0.2.149.29+15 more2009-05-07
CVE-2009-1441 [CRITICAL] CWE-119 CVE-2009-1441: Heap-based buffer overflow in the ParamTraits<SkBitmap>::Read function in Google Chrome before 1.0.1
Heap-based buffer overflow in the ParamTraits::Read function in Google Chrome before 1.0.154.64 allows attackers to leverage renderer access to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to a large bitmap that arrives over the IPC channel.
nvd
CVE-2021-21133P3MEDIUMCVSS 6.5fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21133 [MEDIUM] CVE-2021-21133: Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attac
Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a user to download files to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2019-13673P4HIGHCVSS 7.4fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13673 [HIGH] CWE-862 CVE-2019-13673: Insufficient data validation in developer tools in Google Chrome prior to 77.0.3865.75 allowed a rem
Insufficient data validation in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2012-0725P4CRITICALCVSS 9.3fixed in 18.0.1025.1512012-04-06
CVE-2012-0725 [CRITICAL] CVE-2012-0725: Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to caus
Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0724.
nvd
CVE-2012-0724P4CRITICALCVSS 9.3fixed in 18.0.1025.1512012-04-06
CVE-2012-0724 [CRITICAL] CWE-119 CVE-2012-0724: Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to caus
Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0725.
nvd
CVE-2011-0784P3MEDIUMCVSS 6.8fixed in 9.0.597.842011-02-04
CVE-2011-0784 [MEDIUM] CWE-362 CVE-2011-0784: Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code
Race condition in Google Chrome before 9.0.597.84 allows remote attackers to execute arbitrary code via vectors related to audio.
nvd
CVE-2021-21222P4MEDIUMCVSS 6.5fixed in 90.0.4430.85≥ unspecified, < 90.0.4430.852021-04-26
CVE-2021-21222 [MEDIUM] CWE-787 CVE-2021-21222: Heap buffer overflow in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had
Heap buffer overflow in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2025-11206P4HIGHCVSS 7.1fixed in 141.0.7390.54≥ 141.0.7390.54, < 141.0.7390.542025-11-06
CVE-2025-11206 [HIGH] CWE-122 CVE-2025-11206: Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to p
Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2014-3172P4MEDIUMCVSS 6.4≤ 37.0.2062.93v37.0.2062.0+80 more2014-08-27
CVE-2014-3172 [MEDIUM] CWE-264 CVE-2014-3172: The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome befor
The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL before an attach operation, which allows remote attackers to bypass intended access limitations via an extension that uses a restricted URL, as demonstrated by a chrome:// URL.
nvd
CVE-2026-17750P4HIGHCVSS 7.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17750 [HIGH] CWE-416 CVE-2026-17750: Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potenti
Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17741P3HIGHCVSS 7.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17741 [HIGH] CWE-20 CVE-2026-17741: Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.792
Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17811P4HIGHCVSS 7.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17811 [HIGH] CWE-416 CVE-2026-17811: Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker
Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2016-1628P4MEDIUMCVSS 6.3≤ 48.0.2564.1032016-02-21
CVE-2016-1628 [MEDIUM] CWE-119 CVE-2016-1628: pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, does not validate a certa
pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, does not validate a certain precision value, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted JPEG 2000 image in a PDF document, related to the opj_pi_next_rpcl, opj_pi_next_pcrl, and opj_pi_next_cprl functi
nvd
CVE-2014-1705P4HIGHCVSS 7.5fixed in 33.0.1750.152fixed in 33.0.1750.1542014-03-16
CVE-2014-1705 [HIGH] CWE-787 CVE-2014-1705: Google V8, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154
Google V8, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2016-5150P4HIGHCVSS 8.8≤ 52.0.2743.1162016-09-11
CVE-2016-5150 [HIGH] CWE-416 CVE-2016-5150: WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, has an Indexed Database (aka IndexedDB) API implementation that does not properly restrict key-path evaluation, which allows remote attackers to cause a denial of service (use-after-free) o
nvd
CVE-2016-1695P4HIGHCVSS 8.8≤ 50.0.2661.1022016-06-05
CVE-2016-1695 [HIGH] CVE-2016-1695: Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-1703P4HIGHCVSS 8.8≤ 51.0.2704.632016-06-05
CVE-2016-1703 [HIGH] CVE-2016-1703: Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-1663P4HIGHCVSS 8.8≤ 50.0.2661.872016-05-14
CVE-2016-1663 [HIGH] CVE-2016-1663: The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/Serialize
The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.94, mishandles certain array-buffer data structures, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via
nvd