Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 160 of 292
CVE-2026-11271P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11271 [MEDIUM] CWE-200 CVE-2026-11271: Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote a
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11128P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11128 [MEDIUM] CWE-20 CVE-2026-11128: Inappropriate implementation in Web Share in Google Chrome prior to 149.0.7827.53 allowed a remote a
Inappropriate implementation in Web Share in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11208P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11208 [MEDIUM] CWE-416 CVE-2026-11208: Use after free in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain
Use after free in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11073P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11073 [MEDIUM] CWE-416 CVE-2026-11073: Use after free in WebGL in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain
Use after free in WebGL in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11093P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11093 [MEDIUM] CWE-20 CVE-2026-11093: Inappropriate implementation in Printing in Google Chrome prior to 149.0.7827.53 allowed a remote at
Inappropriate implementation in Printing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11075P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11075 [MEDIUM] CWE-125 CVE-2026-11075: Out of bounds read in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain
Out of bounds read in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11051P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11051 [MEDIUM] CWE-125 CVE-2026-11051: Out of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attack
Out of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11209P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11209 [MEDIUM] CWE-200 CVE-2026-11209: Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote a
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11097P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11097 [MEDIUM] CWE-474 CVE-2026-11097: Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a
Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11121P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11121 [MEDIUM] CWE-20 CVE-2026-11121: Insufficient validation of untrusted input in Skia in Google Chrome prior to 149.0.7827.53 allowed a
Insufficient validation of untrusted input in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11203P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11203 [MEDIUM] CWE-200 CVE-2026-11203: Inappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote
Inappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11140P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11140 [MEDIUM] CWE-20 CVE-2026-11140: Out of bounds read in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker w
Out of bounds read in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11168P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11168 [MEDIUM] CWE-200 CVE-2026-11168: Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11180P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11180 [MEDIUM] CWE-200 CVE-2026-11180: Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacke
Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8550P4MEDIUMCVSS 6.5fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8550 [MEDIUM] CWE-416 CVE-2026-8550: Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who
Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11196P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11196 [MEDIUM] CWE-843 CVE-2026-11196: Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain po
Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted XML file. (Chromium security severity: Medium)
nvd
CVE-2026-14014P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14014 [MEDIUM] CWE-451 CVE-2026-14014: Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attac
Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11653P4MEDIUMCVSS 6.5fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11653 [MEDIUM] CWE-20 CVE-2026-11653: Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11023P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11023 [MEDIUM] CWE-20 CVE-2026-11023: Inappropriate implementation in WebAppInstalls in Google Chrome prior to 149.0.7827.53 allowed a rem
Inappropriate implementation in WebAppInstalls in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-2318P4MEDIUMCVSS 6.5fixed in 145.0.7632.45≥ 145.0.7632.45, < 145.0.7632.452026-02-11
CVE-2026-2318 [MEDIUM] CWE-451 CVE-2026-2318: Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a r
Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd