Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 142 of 292
CVE-2026-17707P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17707 [MEDIUM] CWE-457 CVE-2026-17707: Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attac
Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17674P4MEDIUMCVSS 6.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17674 [MEDIUM] CWE-693 CVE-2026-17674: Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 allowed a remote attack
Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17664P4MEDIUMCVSS 6.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17664 [MEDIUM] CWE-20 CVE-2026-17664: Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed
Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10980P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10980 [MEDIUM] CWE-20 CVE-2026-10980: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allow
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14065P3MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14065 [MEDIUM] CWE-20 CVE-2026-14065: Insufficient validation of untrusted input in PageInfo in Google Chrome prior to 150.0.7871.47 allow
Insufficient validation of untrusted input in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-13926P3MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13926 [MEDIUM] CWE-20 CVE-2026-13926: Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowe
Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13924P3MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13924 [MEDIUM] CWE-20 CVE-2026-13924: Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 150.0.787
Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11008P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11008 [MEDIUM] CWE-20 CVE-2026-11008: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 149.0.7827.53
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11013P3MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11013 [MEDIUM] CWE-20 CVE-2026-11013: Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowe
Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11006P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11006 [MEDIUM] CWE-125 CVE-2026-11006: Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perf
Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11007P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11007 [MEDIUM] CWE-20 CVE-2026-11007: Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 149.0.782
Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13816P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13816 [MEDIUM] CWE-20 CVE-2026-13816: Insufficient validation of untrusted input in File Input in Google Chrome on Android prior to 150.0.
Insufficient validation of untrusted input in File Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13893P3MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13893 [MEDIUM] CWE-20 CVE-2026-13893: Insufficient validation of untrusted input in WebUI in Google Chrome prior to 150.0.7871.47 allowed
Insufficient validation of untrusted input in WebUI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)
nvd
CVE-2026-17764P4MEDIUMCVSS 6.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17764 [MEDIUM] CWE-693 CVE-2026-17764: Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attac
Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17814P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17814 [MEDIUM] CWE-20 CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11016P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11016 [MEDIUM] CWE-20 CVE-2026-11016: Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowe
Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17830P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17830 [MEDIUM] CWE-284 CVE-2026-17830: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-3070P4MEDIUMCVSS 6.5fixed in 135.0.7049.52≥ 135.0.7049.52, < 135.0.7049.522025-04-02
CVE-2025-3070 [MEDIUM] CWE-20 CVE-2025-3070: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 all
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13862P3MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13862 [MEDIUM] CWE-693 CVE-2026-13862: Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on
Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on iOS prior to 150.0.7871.47 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17873P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17873 [MEDIUM] CWE-284 CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 all
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
nvd