Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 155 of 292
CVE-2021-21221P4MEDIUMCVSS 6.5fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21221 [MEDIUM] CWE-20 CVE-2021-21221: Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90.0.4430.72 allowed a
Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
nvd
CVE-2017-15405P4HIGHCVSS 7.0fixed in 61.0.3163.113≥ unspecified, < 61.0.3163.1132019-01-09
CVE-2017-15405 [HIGH] CWE-362 CVE-2017-15405: Inappropriate symlink handling and a race condition in the stateful recovery feature implementation
Inappropriate symlink handling and a race condition in the stateful recovery feature implementation could lead to a persistance established by a malicious code running with root privileges in cryptohomed in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2021-21208P4MEDIUMCVSS 6.5fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21208 [MEDIUM] CWE-20 CVE-2021-21208: Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an
Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying a QR code to perform domain spoofing via a crafted QR code.
nvd
CVE-2023-6512P4MEDIUMCVSS 6.5fixed in 120.0.6099.62≥ 120.0.6099.62, < 120.0.6099.622023-12-06
CVE-2023-6512 [MEDIUM] CWE-838 CVE-2023-6512: Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a rem
Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2018-16088P4MEDIUMCVSS 6.5fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16088 [MEDIUM] CWE-20 CVE-2018-16088: A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowe
A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to download arbitrary files with no user input via a crafted HTML page.
nvd
CVE-2016-5151P4HIGHCVSS 8.8≤ 52.0.2743.1162016-09-11
CVE-2016-5151 [HIGH] CWE-416 CVE-2016-5151: PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mis
PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux mishandles timers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted PDF document, related to fpdfsdk/javascript/JS_Object.cpp and fpdfsdk/javascript/app.cpp.
nvd
CVE-2016-1679P4HIGHCVSS 8.8≤ 50.0.2661.1022016-06-05
CVE-2016-1679 [HIGH] CVE-2016-1679: The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chro
The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does not properly restrict use of getters and setters, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2024-4060P4MEDIUMCVSS 6.5fixed in 124.0.6367.78≥ 124.0.6367.78, < 124.0.6367.782024-05-01
CVE-2024-4060 [MEDIUM] CWE-416 CVE-2024-4060: Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentia
Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11166P4MEDIUMCVSS 6.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11166 [MEDIUM] CWE-79 CVE-2026-11166: Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacke
Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2016-1650P4HIGHCVSS 8.8≤ 49.0.2623.952016-03-29
CVE-2016-1650 [HIGH] CVE-2016-1650: The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/pa
The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/page_capture_api.cc in Google Chrome before 49.0.2623.108 allows attackers to cause a denial of service or possibly have unspecified other impact by triggering an error in creating an MHTML document.
nvd
CVE-2024-4948P4MEDIUMCVSS 6.5fixed in 125.0.6422.60≥ 125.0.6422.60, < 125.0.6422.602024-05-15
CVE-2024-4948 [MEDIUM] CWE-416 CVE-2024-4948: Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentia
Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-4950P4MEDIUMCVSS 6.5fixed in 125.0.6422.60≥ 125.0.6422.60, < 125.0.6422.602024-05-15
CVE-2024-4950 [MEDIUM] CWE-1021 CVE-2024-4950: Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote a
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2016-5153P4HIGHCVSS 8.8≤ 52.0.2743.1162016-09-11
CVE-2016-5153 [HIGH] CWE-19 CVE-2016-5153: The Web Animations implementation in Blink, as used in Google Chrome before 53.0.2785.89 on Windows
The Web Animations implementation in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, improperly relies on list iteration, which allows remote attackers to cause a denial of service (use-after-destruction) or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2022-0461P4MEDIUMCVSS 6.5fixed in 98.0.4758.80≥ unspecified, < 98.0.4758.802022-04-05
CVE-2022-0461 [MEDIUM] CVE-2022-0461: Policy bypass in COOP in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to bypass ifr
Policy bypass in COOP in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to bypass iframe sandbox via a crafted HTML page.
nvd
CVE-2016-5175P4HIGHCVSS 8.8≤ 53.0.2785.1012016-09-25
CVE-2016-5175 [HIGH] CVE-2016-5175: Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.113 allow attackers to cause
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.113 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2024-3515P4MEDIUMCVSS 6.5fixed in 123.0.6312.122≥ 123.0.6312.122, < 123.0.6312.1222024-04-10
CVE-2024-3515 [MEDIUM] CWE-416 CVE-2024-3515: Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potenti
Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-2626P4MEDIUMCVSS 6.5fixed in 123.0.6312.58≥ 123.0.6312.58, < 123.0.6312.582024-03-20
CVE-2024-2626 [MEDIUM] CWE-125 CVE-2024-2626: Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker
Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2020-15988P4MEDIUMCVSS 6.3fixed in 86.0.4240.75≥ unspecified, < 86.0.4240.752020-11-03
CVE-2020-15988 [MEDIUM] CVE-2020-15988: Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allow
Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allowed a remote attacker who convinced the user to open files to execute arbitrary code via a crafted HTML page.
nvd
CVE-2023-5475P4MEDIUMCVSS 6.5fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5475 [MEDIUM] CVE-2023-5475: Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker
Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2022-3309P4MEDIUMCVSS 6.5fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3309 [MEDIUM] CWE-416 CVE-2022-3309: Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote att
Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: Medium)
nvd