cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 151 of 292
CVE-2026-17842P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17842 [MEDIUM] CWE-346 CVE-2026-17842: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11190P3MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11190 [MEDIUM] CWE-284 CVE-2026-11190: Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attack Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2026-17936P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17936 [MEDIUM] CWE-352 CVE-2026-17936: Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote at Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-5901P4MEDIUMCVSS 6.5fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5901 [MEDIUM] CWE-602 CVE-2026-5901: Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attac Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to bypass enterprise host restrictions for cookie modification via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2025-12445P4MEDIUMCVSS 6.5fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12445 [MEDIUM] CWE-288 CVE-2025-12445: Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convince Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2023-3739P3MEDIUMCVSS 6.3fixed in 115.0.5790.131≥ 115.0.5790.131, < 115.0.5790.1312023-08-01
CVE-2023-3739 [MEDIUM] CWE-77 CVE-2023-3739: Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.57 Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbitrary code via a crafted shell script. (Chromium security severity: Low)
nvd
CVE-2014-1731P4HIGHCVSS 7.5fixed in 34.0.1847.131fixed in 34.0.1847.1322014-04-26
CVE-2014-1731 [HIGH] CWE-843 CVE-2014-1731: core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly check renderer state upon a focus event, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "
nvd
CVE-2026-17780P4MEDIUMCVSS 6.3≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17780 [MEDIUM] CWE-284 CVE-2026-17780: Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-13983P4MEDIUMCVSS 6.3fixed in 136.0.7103.59≥ 136.0.7103.59, < 136.0.7103.592025-11-14
CVE-2024-13983 [MEDIUM] CWE-601 CVE-2024-13983: Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security severity: Low)
nvd
CVE-2011-0474P4CRITICALCVSS 10.0fixed in 8.0.552.2372011-01-14
CVE-2011-0474 [CRITICAL] CVE-2011-0474: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading S Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle Cascading Style Sheets (CSS) token sequences in conjunction with cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-3097P4CRITICALCVSS 10.0≤ 19.0.1084.452012-05-16
CVE-2011-3097 [CRITICAL] CWE-20 CVE-2011-3097: The PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial The PDF functionality in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an out-of-bounds write error in the implementation of sampled functions.
nvd
CVE-2011-0476P4CRITICALCVSS 10.0fixed in 8.0.552.2372011-01-14
CVE-2011-0476 [CRITICAL] CWE-119 CVE-2011-0476: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allow remote attackers to cause a Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allow remote attackers to cause a denial of service (stack memory corruption) or possibly have unspecified other impact via a PDF document that triggers an out-of-memory error.
nvd
CVE-2014-3169P4HIGHCVSS 7.5≤ 37.0.2062.93v37.0.2062.0+80 more2014-08-27
CVE-2014-3169 [HIGH] CVE-2014-3169: Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as us Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging script execution that occurs before notification of node removal.
nvd
CVE-2016-1661P4HIGHCVSS 8.0≤ 50.0.2661.872016-05-14
CVE-2016-1661 [HIGH] CWE-20 CVE-2016-1661: Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted web site, related to BindingSecurity.cpp and DOMWin
nvd
CVE-2011-3033P4HIGHCVSS 7.5fixed in 17.0.963.652012-03-05
CVE-2011-3033 [HIGH] CWE-120 CVE-2011-3033: Buffer overflow in Skia, as used in Google Chrome before 17.0.963.65, allows remote attackers to cau Buffer overflow in Skia, as used in Google Chrome before 17.0.963.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-1212P4HIGHCVSS 7.5fixed in 40.0.2214.109fixed in 40.0.2214.1112015-02-06
CVE-2015-1212 [HIGH] CVE-2015-1212: Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 on Windows, OS X, and Lin Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2011-3064P4HIGHCVSS 7.5fixed in 18.0.1025.1422012-03-30
CVE-2011-3064 [HIGH] CWE-416 CVE-2011-3064: Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG clipping.
nvd
CVE-2013-6658P4HIGHCVSS 7.5≤ 33.0.1750.116v33.0.1750.0+95 more2014-02-24
CVE-2013-6658 [HIGH] CWE-399 CVE-2013-6658: Multiple use-after-free vulnerabilities in the layout implementation in Blink, as used in Google Chr Multiple use-after-free vulnerabilities in the layout implementation in Blink, as used in Google Chrome before 33.0.1750.117, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving (1) running JavaScript code during execution of the updateWidgetPositions function or (2) making a call into a pl
nvd
CVE-2014-7940P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7940 [HIGH] CWE-399 CVE-2014-7940: The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 throug The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN revision 293126, as used in Google Chrome before 40.0.2214.91, does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted character sequence.
nvd
CVE-2011-1293P4HIGHCVSS 7.5fixed in 10.0.648.2042011-03-25
CVE-2011-1293 [HIGH] CWE-416 CVE-2011-1293: Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.2 Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
Google Chrome vulnerabilities | cvebase