cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 149 of 292
CVE-2026-10937P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10937 [MEDIUM] CWE-346 CVE-2026-10937: Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote a Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11017P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11017 [MEDIUM] CWE-284 CVE-2026-11017: Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.7827.53 allowed a remot Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17796P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17796 [MEDIUM] CWE-1300 CVE-2026-17796: Side-channel information leakage in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote a Side-channel information leakage in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14007P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14007 [MEDIUM] CWE-602 CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior to 150.0.7871.47 allowed Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13904P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13904 [MEDIUM] CWE-693 CVE-2026-13904: Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5903P4MEDIUMCVSS 6.5fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5903 [MEDIUM] CWE-693 CVE-2026-5903: Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14070P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14070 [MEDIUM] CWE-457 CVE-2026-14070: Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtai Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14050P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14050 [MEDIUM] CWE-693 CVE-2026-14050: Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remot Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11263P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11263 [MEDIUM] CWE-693 CVE-2026-11263: Insufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827 Insufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-15778P4MEDIUMCVSS 6.5fixed in 150.0.7871.125≥ 150.0.7871.125, < 150.0.7871.1252026-07-14
CVE-2026-15778 [MEDIUM] CWE-20 CVE-2026-15778: Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 al Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13886P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13886 [MEDIUM] CWE-693 CVE-2026-13886: Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17824P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17824 [MEDIUM] CWE-284 CVE-2026-17824: Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 151.0.7922.72 allowed a r Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17946P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17946 [MEDIUM] CWE-457 CVE-2026-17946: Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14069P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14069 [MEDIUM] CWE-472 CVE-2026-14069: Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtai Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17792P4MEDIUMCVSS 6.5≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17792 [MEDIUM] CWE-451 CVE-2026-17792: Inappropriate implementation in Credential Management in Google Chrome prior to 151.0.7922.72 allowe Inappropriate implementation in Credential Management in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17793P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17793 [MEDIUM] CWE-451 CVE-2026-17793: Inappropriate implementation in Messages in Google Chrome on Android prior to 151.0.7922.72 allowed Inappropriate implementation in Messages in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17985P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17985 [MEDIUM] CWE-602 CVE-2026-17985: Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote a Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17931P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17931 [MEDIUM] CWE-693 CVE-2026-17931: Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote at Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17813P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17813 [MEDIUM] CWE-602 CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 all Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17953P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17953 [MEDIUM] CWE-602 CVE-2026-17953: Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 allowe Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
Google Chrome vulnerabilities | cvebase