Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 146 of 292
CVE-2023-2460P4HIGHCVSS 7.1fixed in 113.0.5672.63≥ 113.0.5672.63, < 113.0.5672.632023-05-03
CVE-2023-2460 [HIGH] CVE-2023-2460: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 all
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to bypass file access checks via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2021-21212P4MEDIUMCVSS 6.5fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21212 [MEDIUM] CVE-2021-21212: Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 90.0.4430.72 allowe
Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 90.0.4430.72 allowed a remote attacker to potentially compromise WiFi connection security via a malicious WAP.
nvd
CVE-2026-17744P4HIGHCVSS 7.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17744 [HIGH] CWE-269 CVE-2026-17744: Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed
Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17867P4HIGHCVSS 7.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17867 [HIGH] CWE-20 CVE-2026-17867: Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a
Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2016-5161P4HIGHCVSS 8.8≤ 52.0.2743.1162016-09-11
CVE-2016-5161 [HIGH] CWE-704 CVE-2016-5161: The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink, as us
The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles custom properties, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site that le
nvd
CVE-2016-1705P4HIGHCVSS 8.8≤ 51.0.2704.1062016-07-23
CVE-2016-1705 [HIGH] CVE-2016-1705: Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.82 allow attackers to cause a
Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.82 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2016-1660P4HIGHCVSS 8.8≤ 50.0.2661.872016-05-14
CVE-2016-1660 [HIGH] CWE-20 CVE-2016-1660: Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and
Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2016-1704P4HIGHCVSS 8.8≤ 51.0.2704.842016-07-03
CVE-2016-1704 [HIGH] CVE-2016-1704: Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.103 allow attackers to cause
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.103 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2014-7928P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7928 [HIGH] CWE-19 CVE-2014-7928: hydrogen.cc in Google V8, as used Google Chrome before 40.0.2214.91, does not properly handle arrays
hydrogen.cc in Google V8, as used Google Chrome before 40.0.2214.91, does not properly handle arrays with holes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code that triggers an array copy.
nvd
CVE-2016-1708P4HIGHCVSS 8.8≤ 51.0.2704.1062016-07-23
CVE-2016-1708 [HIGH] CWE-416 CVE-2016-1708: The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome
The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82 does not properly consider object lifetimes during progress observation, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2025-1122P4MEDIUMCVSS 6.7v122.0.6261.1322025-04-15
CVE-2025-1122 [MEDIUM] CWE-787 CVE-2025-1122: Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards a
Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and
Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
nvd
CVE-2014-7927P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7927 [HIGH] CWE-189 CVE-2014-7927: The SimplifiedLowering::DoLoadBuffer function in compiler/simplified-lowering.cc in Google V8, as us
The SimplifiedLowering::DoLoadBuffer function in compiler/simplified-lowering.cc in Google V8, as used in Google Chrome before 40.0.2214.91, does not properly choose an integer data type, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-1701P4HIGHCVSS 8.8≤ 51.0.2704.632016-06-05
CVE-2016-1701 [HIGH] CVE-2016-1701: The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
nvd
CVE-2025-1292P4MEDIUMCVSS 6.7v122.0.6261.1322025-04-15
CVE-2025-1292 [MEDIUM] CWE-787 CVE-2025-1292: Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boar
Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and
bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
nvd
CVE-2026-17668P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17668 [MEDIUM] CWE-457 CVE-2026-17668: Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17667P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17667 [MEDIUM] CWE-457 CVE-2026-17667: Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17714P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17714 [MEDIUM] CWE-457 CVE-2026-17714: Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obta
Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17703P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17703 [MEDIUM] CWE-602 CVE-2026-17703: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 all
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17683P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17683 [MEDIUM] CWE-200 CVE-2026-17683: Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attac
Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10938P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10938 [MEDIUM] CWE-20 CVE-2026-10938: Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attac
Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd