cbcvebase.

Google Chrome vulnerabilities

5,463 known vulnerabilities affecting google/chrome.

Total CVEs
5,463
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL440HIGH2725MEDIUM2233LOW65

Vulnerabilities

Page 15 of 274
CVE-2026-11634P3CRITICALCVSS 9.6fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11634 [CRITICAL] CWE-416 CVE-2026-11634: Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attac Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-11153P3CRITICALCVSS 9.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11153 [CRITICAL] CWE-1300 CVE-2026-11153: Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote a Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2021-21122P3HIGHCVSS 8.8fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21122 [HIGH] CWE-416 CVE-2021-21122: Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentia Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21120P3HIGHCVSS 8.8fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21120 [HIGH] CWE-416 CVE-2021-21120: Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potenti Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21119P3HIGHCVSS 8.8fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21119 [HIGH] CWE-416 CVE-2021-21119: Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had com Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2014-3176P3CRITICALCVSS 10.0≤ 37.0.2062.93v37.0.2062.0+80 more2014-08-27
CVE-2014-3176 [CRITICAL] CWE-94 CVE-2014-3176: Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the s Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3177.
nvd
CVE-2026-9891P3CRITICALCVSS 9.0fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9891 [CRITICAL] CWE-416 CVE-2026-9891: Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical)
nvd
CVE-2021-21225P3HIGHCVSS 8.8fixed in 90.0.4430.85≥ unspecified, < 90.0.4430.852021-04-26
CVE-2021-21225 [HIGH] CWE-787 CVE-2021-21225: Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker t Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-5858P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5858 [HIGH] CWE-122 CVE-2026-5858: Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to e Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2021-21128P3HIGHCVSS 8.8fixed in 88.0.4324.96≥ unspecified, < 88.0.4324.962021-02-09
CVE-2021-21128 [HIGH] CWE-787 CVE-2021-21128: Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to po Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-9120P3HIGHCVSS 8.8fixed in 148.0.7778.178≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9120 [HIGH] CWE-416 CVE-2026-9120: Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execu Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8517P3HIGHCVSS 8.8fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8517 [HIGH] CWE-664 CVE-2026-8517: Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10903P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10903 [HIGH] CWE-416 CVE-2026-10903: Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10947P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10947 [HIGH] CWE-416 CVE-2026-10947: Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10943P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10943 [HIGH] CWE-416 CVE-2026-10943: Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10948P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10948 [HIGH] CWE-416 CVE-2026-10948: Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5860P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5860 [HIGH] CWE-416 CVE-2026-5860: Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execut Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10882P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10882 [HIGH] CWE-416 CVE-2026-10882: Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execu Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10975P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10975 [HIGH] CWE-416 CVE-2026-10975: Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10982P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10982 [HIGH] CWE-416 CVE-2026-10982: Use after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute Use after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase