Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 145 of 292
CVE-2015-6773P4HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-6773 [HIGH] CWE-119 CVE-2015-6773: The convolution implementation in Skia, as used in Google Chrome before 47.0.2526.73, does not prope
The convolution implementation in Skia, as used in Google Chrome before 47.0.2526.73, does not properly constrain row lengths, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted graphics data.
nvd
CVE-2015-6762P4HIGHCVSS 7.5≤ 45.0.2454.1012015-10-15
CVE-2015-6762 [HIGH] CWE-254 CVE-2015-6762: The CSSFontFaceSrcValue::fetch function in core/css/CSSFontFaceSrcValue.cpp in the Cascading Style S
The CSSFontFaceSrcValue::fetch function in core/css/CSSFontFaceSrcValue.cpp in the Cascading Style Sheets (CSS) implementation in Blink, as used in Google Chrome before 46.0.2490.71, does not use the CORS cross-origin request algorithm when a font's URL appears to be a same-origin URL, which allows remote web servers to bypass the Same Origin Policy via
nvd
CVE-2014-3192P4HIGHCVSS 7.5≤ 38.0.2125.72014-10-08
CVE-2014-3192 [HIGH] CWE-416 CVE-2014-3192: Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/Pro
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2021-21136P3MEDIUMCVSS 6.5fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21136 [MEDIUM] CWE-346 CVE-2021-21136: Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2015-1294P4HIGHCVSS 7.5≤ 44.0.24032015-09-03
CVE-2015-1294 [HIGH] CVE-2015-1294: Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Ski
Use-after-free vulnerability in the SkMatrix::invertNonIdentity function in core/SkMatrix.cpp in Skia, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering the use of matrix elements that lead to an infinite result during an inversion calculation.
nvd
CVE-2011-3898P3HIGHCVSS 7.5fixed in 15.0.874.1202011-11-11
CVE-2011-3898 [HIGH] CWE-269 CVE-2011-3898: Google Chrome before 15.0.874.120, when Java Runtime Environment (JRE) 7 is used, does not request u
Google Chrome before 15.0.874.120, when Java Runtime Environment (JRE) 7 is used, does not request user confirmation before applet execution begins, which allows remote attackers to have an unspecified impact via a crafted applet.
nvd
CVE-2014-1703P4HIGHCVSS 7.5≤ 33.0.1750.146v33.0.1750.0+105 more2014-03-16
CVE-2014-1703 [HIGH] CWE-399 CVE-2014-1703: Use-after-free vulnerability in the WebSocketDispatcherHost::SendOrDrop function in content/browser/
Use-after-free vulnerability in the WebSocketDispatcherHost::SendOrDrop function in content/browser/renderer_host/websocket_dispatcher_host.cc in the Web Sockets implementation in Google Chrome before 33.0.1750.149 might allow remote attackers to bypass the sandbox protection mechanism by leveraging an incorrect deletion in a certain failure case.
nvd
CVE-2016-1691P4HIGHCVSS 7.5≤ 50.0.2661.1022016-06-05
CVE-2016-1691 [HIGH] CWE-119 CVE-2016-1691: Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote
Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted curves, related to SkOpCoincidence.cpp and SkPathOpsCommon.cpp.
nvd
CVE-2013-6665P4HIGHCVSS 7.5≤ 33.0.1750.144v33.0.1750.0+104 more2014-03-05
CVE-2013-6665 [HIGH] CWE-119 CVE-2013-6665: Heap-based buffer overflow in the ResourceProvider::InitializeSoftware function in cc/resources/reso
Heap-based buffer overflow in the ResourceProvider::InitializeSoftware function in cc/resources/resource_provider.cc in Google Chrome before 33.0.1750.146 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large texture size that triggers improper memory allocation in the software renderer.
nvd
CVE-2022-0301P4HIGHCVSS 7.8fixed in 97.0.4692.99≥ unspecified, < 97.0.4692.992022-02-12
CVE-2022-0301 [HIGH] CWE-416 CVE-2022-0301: Heap buffer overflow in DevTools in Google Chrome prior to 97.0.4692.99 allowed an attacker who conv
Heap buffer overflow in DevTools in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2013-6643P4HIGHCVSS 7.5fixed in 32.0.1700.77fixed in 32.0.1700.762014-01-16
CVE-2013-6643 [HIGH] CWE-287 CVE-2013-6643: The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubbl
The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers to trigger a sync with an arbitrary Google account by leveraging improper handling of the closing of an untrusted signin confirm dialo
nvd
CVE-2020-15983P4HIGHCVSS 7.8fixed in 86.0.4240.75≥ unspecified, < 86.0.4240.752020-11-03
CVE-2020-15983 [HIGH] CWE-20 CVE-2020-15983: Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a l
Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2011-0480P4CRITICALCVSS 9.3fixed in 8.0.552.2372011-01-14
CVE-2011-0480 [CRITICAL] CWE-120 CVE-2011-0480: Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome
Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel
nvd
CVE-2010-1825P4CRITICALCVSS 9.3fixed in 6.0.472.592010-09-24
CVE-2010-1825 [CRITICAL] CWE-416 CVE-2010-1825: Use-after-free vulnerability in WebKit, as used in Google Chrome before 6.0.472.59, allows remote at
Use-after-free vulnerability in WebKit, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to nested SVG elements.
nvd
CVE-2019-5798P4MEDIUMCVSS 6.5fixed in 73.0.3683.75vprior to 73.0.3683.752019-05-23
CVE-2019-5798 [MEDIUM] CWE-125 CVE-2019-5798: Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote atta
Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2009-1442P3MEDIUMCVSS 6.8≤ 1.0.154.53v0.2.149.29+20 more2009-05-07
CVE-2009-1442 [MEDIUM] CWE-189 CVE-2009-1442: Multiple integer overflows in Skia, as used in Google Chrome 1.x before 1.0.154.64 and 2.x, and poss
Multiple integer overflows in Skia, as used in Google Chrome 1.x before 1.0.154.64 and 2.x, and possibly Android, might allow remote attackers to execute arbitrary code in the renderer process via a crafted (1) image or (2) canvas.
nvd
CVE-2011-2335P4HIGHCVSS 7.5vbefore Blink M122019-11-12
CVE-2011-2335 [HIGH] CWE-415 CVE-2011-2335: A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSe
A double-free vulnerability exists in WebKit in Google Chrome before Blink M12 in the WebCore::CSSSelector function.
nvd
CVE-2019-13668P4HIGHCVSS 7.4fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13668 [HIGH] CWE-281 CVE-2019-13668: Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a
Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6426P4MEDIUMCVSS 6.5fixed in 80.0.3987.149≥ unspecified, < 80.0.3987.1492020-03-23
CVE-2020-6426 [MEDIUM] CWE-787 CVE-2020-6426: Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13750P4MEDIUMCVSS 6.5fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13750 [MEDIUM] CWE-20 CVE-2019-13750: Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attac
Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.
nvd