Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 154 of 292
CVE-2015-1218P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1218 [HIGH] CVE-2015-1218: Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome
Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger movement of a SCRIPT element to different documents, related to (1) the HTMLScriptElement::didMoveToNewDocument function i
nvd
CVE-2012-2876P4HIGHCVSS 7.5≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2876 [HIGH] CWE-119 CVE-2012-2876: Buffer overflow in the SSE2 optimization functionality in Google Chrome before 22.0.1229.79 allows r
Buffer overflow in the SSE2 optimization functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-2883P4HIGHCVSS 7.5≤ 28.0.1500.94v28.0.1500.0+67 more2013-07-31
CVE-2013-2883 [HIGH] CWE-399 CVE-2013-2883: Use-after-free vulnerability in Google Chrome before 28.0.1500.95 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 28.0.1500.95 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to deleting the registration of a MutationObserver object.
nvd
CVE-2013-6652P4HIGHCVSS 7.5≤ 33.0.1750.116v33.0.1750.0+95 more2014-02-24
CVE-2013-6652 [HIGH] CWE-22 CVE-2013-6652: Directory traversal vulnerability in sandbox/win/src/named_pipe_dispatcher.cc in Google Chrome befor
Directory traversal vulnerability in sandbox/win/src/named_pipe_dispatcher.cc in Google Chrome before 33.0.1750.117 on Windows allows attackers to bypass intended named-pipe policy restrictions in the sandbox via vectors related to (1) lack of checks for .. (dot dot) sequences or (2) lack of use of the \\?\ protection mechanism.
nvd
CVE-2020-6506P4MEDIUMCVSS 6.5fixed in 83.0.4103.106≥ unspecified, < 83.0.4103.1062020-07-22
CVE-2020-6506 [MEDIUM] CVE-2020-6506: Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowe
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page.
nvd
CVE-2010-2108P4HIGHCVSS 7.5fixed in 5.0.375.552010-05-28
CVE-2010-2108 [HIGH] CVE-2010-2108: Unspecified vulnerability in Google Chrome before 5.0.375.55 allows remote attackers to bypass the w
Unspecified vulnerability in Google Chrome before 5.0.375.55 allows remote attackers to bypass the whitelist-mode plugin blocker via unknown vectors.
nvd
CVE-2016-1700P4HIGHCVSS 7.5≤ 51.0.2704.632016-06-05
CVE-2016-1700 [HIGH] CVE-2016-1700: extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not conside
extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to extensions.
nvd
CVE-2010-4201P4CRITICALCVSS 9.8fixed in 7.0.517.442010-11-06
CVE-2010-4201 [CRITICAL] CWE-416 CVE-2010-4201: Use-after-free vulnerability in Google Chrome before 7.0.517.44 allows remote attackers to cause a d
Use-after-free vulnerability in Google Chrome before 7.0.517.44 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text control selections.
nvd
CVE-2019-5880P4HIGHCVSS 7.4fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-5880 [HIGH] CWE-200 CVE-2019-5880: Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote att
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2010-2647P4CRITICALCVSS 9.3fixed in 5.0.375.992010-07-06
CVE-2010-2647 [CRITICAL] CWE-119 CVE-2010-2647: Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corrupt
Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an invalid SVG document.
nvd
CVE-2010-2648P4CRITICALCVSS 9.3fixed in 5.0.375.992010-07-06
CVE-2010-2648 [CRITICAL] CWE-119 CVE-2010-2648: The implementation of the Unicode Bidirectional Algorithm (aka Bidi algorithm or UBA) in Google Chro
The implementation of the Unicode Bidirectional Algorithm (aka Bidi algorithm or UBA) in Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-2844P4CRITICALCVSS 9.3≤ 20.0.1132.56v20.0.1132.0+48 more2012-07-12
CVE-2012-2844 [CRITICAL] CVE-2012-2844: The PDF functionality in Google Chrome before 20.0.1132.57 does not properly handle JavaScript code,
The PDF functionality in Google Chrome before 20.0.1132.57 does not properly handle JavaScript code, which allows remote attackers to cause a denial of service (incorrect object access) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2018-18351P4MEDIUMCVSS 6.5fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18351 [MEDIUM] CWE-20 CVE-2018-18351: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google C
Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
nvd
CVE-2010-4486P4CRITICALCVSS 9.3≤ 8.0.552.2142010-12-07
CVE-2010-4486 [CRITICAL] CWE-399 CVE-2010-4486: Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to history handling.
nvd
CVE-2020-6401P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6401 [MEDIUM] CWE-20 CVE-2020-6401: Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2021-21210P4MEDIUMCVSS 6.5fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21210 [MEDIUM] CVE-2021-21210: Inappropriate implementation in Network in Google Chrome prior to 90.0.4430.72 allowed a remote atta
Inappropriate implementation in Network in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially access local UDP ports via a crafted HTML page.
nvd
CVE-2021-21182P4MEDIUMCVSS 6.5fixed in 89.0.4389.72≥ unspecified, < 89.0.4389.722021-03-09
CVE-2021-21182 [MEDIUM] CWE-863 CVE-2021-21182: Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.4389.72 allowed a remo
Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2021-30531P4MEDIUMCVSS 6.5fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30531 [MEDIUM] CVE-2021-30531: Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 al
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2026-17888P4HIGHCVSS 7.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17888 [HIGH] CWE-20 CVE-2026-17888: Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed
Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)
nvd
CVE-2019-5835P4MEDIUMCVSS 6.5fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5835 [MEDIUM] CWE-125 CVE-2019-5835: Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attack
Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd