Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 149 of 292
CVE-2026-10937P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10937 [MEDIUM] CWE-346 CVE-2026-10937: Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote a
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11017P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11017 [MEDIUM] CWE-284 CVE-2026-11017: Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.7827.53 allowed a remot
Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17796P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17796 [MEDIUM] CWE-1300 CVE-2026-17796: Side-channel information leakage in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote a
Side-channel information leakage in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14007P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14007 [MEDIUM] CWE-602 CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior to 150.0.7871.47 allowed
Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13904P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13904 [MEDIUM] CWE-693 CVE-2026-13904: Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed
Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5903P4MEDIUMCVSS 6.5fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5903 [MEDIUM] CWE-693 CVE-2026-5903: Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who
Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14070P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14070 [MEDIUM] CWE-457 CVE-2026-14070: Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtai
Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14050P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14050 [MEDIUM] CWE-693 CVE-2026-14050: Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remot
Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11263P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11263 [MEDIUM] CWE-693 CVE-2026-11263: Insufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827
Insufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-15778P4MEDIUMCVSS 6.5fixed in 150.0.7871.125≥ 150.0.7871.125, < 150.0.7871.1252026-07-14
CVE-2026-15778 [MEDIUM] CWE-20 CVE-2026-15778: Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 al
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13886P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13886 [MEDIUM] CWE-693 CVE-2026-13886: Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed
Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17824P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17824 [MEDIUM] CWE-284 CVE-2026-17824: Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 151.0.7922.72 allowed a r
Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17946P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17946 [MEDIUM] CWE-457 CVE-2026-17946: Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had
Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14069P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14069 [MEDIUM] CWE-472 CVE-2026-14069: Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtai
Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17792P4MEDIUMCVSS 6.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17792 [MEDIUM] CWE-451 CVE-2026-17792: Inappropriate implementation in Credential Management in Google Chrome prior to 151.0.7922.72 allowe
Inappropriate implementation in Credential Management in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17793P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17793 [MEDIUM] CWE-451 CVE-2026-17793: Inappropriate implementation in Messages in Google Chrome on Android prior to 151.0.7922.72 allowed
Inappropriate implementation in Messages in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17985P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17985 [MEDIUM] CWE-602 CVE-2026-17985: Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote a
Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17931P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17931 [MEDIUM] CWE-693 CVE-2026-17931: Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote at
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17813P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17813 [MEDIUM] CWE-602 CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 all
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17953P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17953 [MEDIUM] CWE-602 CVE-2026-17953: Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 allowe
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd