Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 157 of 292
CVE-2026-13953P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13953 [MEDIUM] CWE-284 CVE-2026-13953: Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote a
Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13866P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13866 [MEDIUM] CWE-20 CVE-2026-13866: Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a r
Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9122P4MEDIUMCVSS 6.5fixed in 148.0.7778.179≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9122 [MEDIUM] CWE-125 CVE-2026-9122: Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker
Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17800P4MEDIUMCVSS 6.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17800 [MEDIUM] CWE-1300 CVE-2026-17800: Inappropriate implementation in MediaRecording in Google Chrome prior to 151.0.7922.72 allowed a rem
Inappropriate implementation in MediaRecording in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14125P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14125 [MEDIUM] CWE-457 CVE-2026-14125: Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obta
Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14388P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14388 [MEDIUM] CWE-125 CVE-2026-14388: Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obt
Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14386P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14386 [MEDIUM] CWE-125 CVE-2026-14386: Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obt
Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14384P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14384 [MEDIUM] CWE-125 CVE-2026-14384: Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote atta
Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13931P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13931 [MEDIUM] CWE-284 CVE-2026-13931: Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a r
Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10996P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10996 [MEDIUM] CWE-346 CVE-2026-10996: Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote att
Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11019P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11019 [MEDIUM] CWE-290 CVE-2026-11019: Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed
Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13795P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13795 [MEDIUM] CWE-602 CVE-2026-13795: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 all
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14088P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14088 [MEDIUM] CWE-457 CVE-2026-14088: Uninitialized Use in Canvas in Google Chrome on Android prior to 150.0.7871.47 allowed a remote atta
Uninitialized Use in Canvas in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14051P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14051 [MEDIUM] CWE-457 CVE-2026-14051: Uninitialized Use in GamepadAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker wh
Uninitialized Use in GamepadAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14059P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14059 [MEDIUM] CWE-693 CVE-2026-14059: Insufficient policy enforcement in Related-Website-Sets in Google Chrome prior to 150.0.7871.47 allo
Insufficient policy enforcement in Related-Website-Sets in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14021P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14021 [MEDIUM] CWE-20 CVE-2026-14021: Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed
Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14085P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14085 [MEDIUM] CWE-1300 CVE-2026-14085: Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote att
Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14103P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14103 [MEDIUM] CWE-416 CVE-2026-14103: Use after free in SSL in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker
Use after free in SSL in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-13985P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13985 [MEDIUM] CWE-451 CVE-2026-13985: Inappropriate implementation in MediaCapture in Google Chrome prior to 150.0.7871.47 allowed a remot
Inappropriate implementation in MediaCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14146P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14146 [MEDIUM] CWE-200 CVE-2026-14146: Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacke
Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd