Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 143 of 292
CVE-2026-10997P3MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10997 [MEDIUM] CWE-732 CVE-2026-10997: Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an att
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2026-17791P4MEDIUMCVSS 6.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17791 [MEDIUM] CWE-20 CVE-2026-17791: Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allow
Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17831P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17831 [MEDIUM] CWE-20 CVE-2026-17831: Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allo
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17926P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17926 [MEDIUM] CWE-20 CVE-2026-17926: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allow
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17921P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17921 [MEDIUM] CWE-20 CVE-2026-17921: Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 all
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17988P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17988 [MEDIUM] CWE-20 CVE-2026-17988: Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 all
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-13908P3MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13908 [MEDIUM] CWE-20 CVE-2026-13908: Insufficient validation of untrusted input in Omnibox in Google Chrome on iOS prior to 150.0.7871.47
Insufficient validation of untrusted input in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Medium)
nvd
CVE-2026-13876P3MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13876 [MEDIUM] CWE-693 CVE-2026-13876: Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker
Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bypass content security policy via malicious network traffic. (Chromium security severity: Medium)
nvd
CVE-2026-17825P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17825 [MEDIUM] CWE-284 CVE-2026-17825: Insufficient policy enforcement in Passwords in Google Chrome on Android prior to 151.0.7922.72 allo
Insufficient policy enforcement in Passwords in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17917P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17917 [MEDIUM] CWE-284 CVE-2026-17917: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 all
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17986P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17986 [MEDIUM] CWE-284 CVE-2026-17986: Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remot
Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11258P3MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11258 [MEDIUM] CWE-284 CVE-2026-11258: Inappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a
Inappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11283P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11283 [MEDIUM] CWE-20 CVE-2026-11283: Insufficient validation of untrusted input in Shortcuts in Google Chrome on Mac prior to 149.0.7827.
Insufficient validation of untrusted input in Shortcuts in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)
nvd
CVE-2026-17882P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17882 [MEDIUM] CWE-693 CVE-2026-17882: Policy bypass in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convince
Policy bypass in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2026-11038P3MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11038 [MEDIUM] CWE-20 CVE-2026-11038: Insufficient policy enforcement in Subresource Integrity in Google Chrome prior to 149.0.7827.53 all
Insufficient policy enforcement in Subresource Integrity in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via malicious network traffic. (Chromium security severity: Medium)
nvd
CVE-2026-11210P3MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11210 [MEDIUM] CWE-284 CVE-2026-11210: Inappropriate implementation in Safe Browsing in Google Chrome prior to 149.0.7827.53 allowed a remo
Inappropriate implementation in Safe Browsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted RAR file. (Chromium security severity: Medium)
nvd
CVE-2025-12431P4MEDIUMCVSS 6.5fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12431 [MEDIUM] CWE-288 CVE-2025-12431: Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attack
Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2026-18014P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-18014 [MEDIUM] CWE-20 CVE-2026-18014: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allow
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)
nvd
CVE-2021-21137P4MEDIUMCVSS 6.5fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21137 [MEDIUM] CWE-74 CVE-2021-21137: Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote att
Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
nvd
CVE-2016-1671P4HIGHCVSS 8.1≤ 50.0.2661.872016-05-14
CVE-2016-1671 [HIGH] CWE-22 CVE-2016-1671: Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, whi
Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversal attacks via a file: URL, related to net/base/escape.cc and net/base/filename_util.cc.
nvd