Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 156 of 292
CVE-2024-5839P4MEDIUMCVSS 6.5fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5839 [MEDIUM] CWE-474 CVE-2024-5839: Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a r
Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-5843P4MEDIUMCVSS 6.5fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5843 [MEDIUM] CWE-843 CVE-2024-5843: Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote a
Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate security UI via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2021-4323P4MEDIUMCVSS 6.5fixed in 90.0.4430.72≥ 90.0.4430.72, < 90.0.4430.722023-07-29
CVE-2021-4323 [MEDIUM] CVE-2021-4323: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allo
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to access local files via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2025-5065P4MEDIUMCVSS 6.5fixed in 137.0.7151.55≥ 137.0.7151.55, < 137.0.7151.552025-05-27
CVE-2025-5065 [MEDIUM] CWE-451 CVE-2025-5065: Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed
Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2013-6629P4MEDIUMCVSS 5.0fixed in 31.0.1650.482013-11-19
CVE-2013-6629 [MEDIUM] CWE-200 CVE-2013-6629: The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive
nvd
CVE-2026-10994P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10994 [MEDIUM] CWE-457 CVE-2026-10994: Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obta
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13923P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13923 [MEDIUM] CWE-457 CVE-2026-13923: Uninitialized Use in GPU in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacke
Uninitialized Use in GPU in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13943P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13943 [MEDIUM] CWE-457 CVE-2026-13943: Uninitialized Use in CSS in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacke
Uninitialized Use in CSS in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13790P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13790 [MEDIUM] CWE-1300 CVE-2026-13790: Side-channel information leakage in Scroll in Google Chrome prior to 150.0.7871.47 allowed a remote
Side-channel information leakage in Scroll in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13889P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13889 [MEDIUM] CWE-20 CVE-2026-13889: Side-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47
Side-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-15770P4MEDIUMCVSS 6.5fixed in 150.0.7871.125≥ 150.0.7871.125, < 150.0.7871.1252026-07-14
CVE-2026-15770 [MEDIUM] CWE-457 CVE-2026-15770: Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-15766P4MEDIUMCVSS 6.5fixed in 150.0.7871.125≥ 150.0.7871.125, < 150.0.7871.1252026-07-14
CVE-2026-15766 [MEDIUM] CWE-457 CVE-2026-15766: Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obta
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13954P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13954 [MEDIUM] CWE-284 CVE-2026-13954: Insufficient policy enforcement in XML in Google Chrome on Android prior to 150.0.7871.47 allowed a
Insufficient policy enforcement in XML in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10944P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10944 [MEDIUM] CWE-693 CVE-2026-10944: Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a
Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10950P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10950 [MEDIUM] CWE-693 CVE-2026-10950: Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a
Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10999P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10999 [MEDIUM] CWE-190 CVE-2026-10999: Integer overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attack
Integer overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13936P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13936 [MEDIUM] CWE-284 CVE-2026-13936: Inappropriate implementation in Passwords in Google Chrome on Android prior to 150.0.7871.47 allowed
Inappropriate implementation in Passwords in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13809P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13809 [MEDIUM] CWE-1300 CVE-2026-13809: Side-channel information leakage in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 all
Side-channel information leakage in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13828P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13828 [MEDIUM] CWE-284 CVE-2026-13828: Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote
Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13818P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13818 [MEDIUM] CWE-284 CVE-2026-13818: Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote a
Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
nvd