Google Chrome vulnerabilities
4,008 known vulnerabilities affecting google/chrome.
Total CVEs
4,008
CISA KEV
74
actively exploited
Public exploits
64
Exploited in wild
65
Severity breakdown
CRITICAL298HIGH2025MEDIUM1626LOW17UNKNOWN42
Vulnerabilities
Page 162 of 201
CVE-2013-2841HIGHCVSS 7.5≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2841 [HIGH] CWE-399 CVE-2013-2841: Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of Pepper resources.
nvd
CVE-2013-2838MEDIUMCVSS 5.0≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2838 [MEDIUM] CWE-119 CVE-2013-2838: Google V8, as used in Google Chrome before 27.0.1453.93, allows remote attackers to cause a denial o
Google V8, as used in Google Chrome before 27.0.1453.93, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2013-2849MEDIUMCVSS 4.3≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2849 [MEDIUM] CWE-79 CVE-2013-2849: Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome before 27.0.1453.93 allow user-
Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome before 27.0.1453.93 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.
nvd
CVE-2013-2848MEDIUMCVSS 5.0≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2848 [MEDIUM] CWE-200 CVE-2013-2848: The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitiv
The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2013-2847MEDIUMCVSS 6.8≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2847 [MEDIUM] CWE-362 CVE-2013-2847: Race condition in the workers implementation in Google Chrome before 27.0.1453.93 allows remote atta
Race condition in the workers implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-0924HIGHCVSS 7.5≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0924 [HIGH] CWE-264 CVE-2013-0924: The extension functionality in Google Chrome before 26.0.1410.43 does not verify that use of the per
The extension functionality in Google Chrome before 26.0.1410.43 does not verify that use of the permissions API is consistent with file permissions, which has unspecified impact and attack vectors.
nvd
CVE-2013-0919HIGHCVSS 7.5≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0919 [HIGH] CWE-399 CVE-2013-0919: Use-after-free vulnerability in Google Chrome before 26.0.1410.43 on Linux allows remote attackers t
Use-after-free vulnerability in Google Chrome before 26.0.1410.43 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging the presence of an extension that creates a pop-up window.
nvd
CVE-2013-0922HIGHCVSS 7.5≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0922 [HIGH] CWE-264 CVE-2013-0922: Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web
Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web sites that require HTTP Basic Authentication, which has unspecified impact and attack vectors.
nvd
CVE-2013-0916HIGHCVSS 7.5≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0916 [HIGH] CWE-399 CVE-2013-0916: Use-after-free vulnerability in the Web Audio implementation in Google Chrome before 26.0.1410.43 al
Use-after-free vulnerability in the Web Audio implementation in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-0920HIGHCVSS 7.5≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0920 [HIGH] CWE-399 CVE-2013-0920: Use-after-free vulnerability in the extension bookmarks API in Google Chrome before 26.0.1410.43 all
Use-after-free vulnerability in the extension bookmarks API in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-0925HIGHCVSS 7.5≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0925 [HIGH] CWE-264 CVE-2013-0925: Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission:
Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission::kTab) permission before providing a URL to this extension, which has unspecified impact and remote attack vectors.
nvd
CVE-2013-0918MEDIUMCVSS 6.8≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0918 [MEDIUM] CWE-264 CVE-2013-0918: Google Chrome before 26.0.1410.43 does not prevent navigation to developer tools in response to a dr
Google Chrome before 26.0.1410.43 does not prevent navigation to developer tools in response to a drag-and-drop operation, which allows user-assisted remote attackers to have an unspecified impact via a crafted web site.
nvd
CVE-2013-0917MEDIUMCVSS 5.0≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0917 [MEDIUM] CWE-119 CVE-2013-0917: The URL loader in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of ser
The URL loader in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2013-0923MEDIUMCVSS 5.0≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0923 [MEDIUM] CWE-119 CVE-2013-0923: The USB Apps API in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of s
The USB Apps API in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2013-0926MEDIUMCVSS 6.8≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0926 [MEDIUM] CWE-20 CVE-2013-0926: Google Chrome before 26.0.1410.43 does not properly handle active content in an EMBED element during
Google Chrome before 26.0.1410.43 does not properly handle active content in an EMBED element during a copy-and-paste operation, which allows user-assisted remote attackers to have an unspecified impact via a crafted web site.
nvd
CVE-2013-0921MEDIUMCVSS 6.8≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0921 [MEDIUM] CWE-264 CVE-2013-0921: The Isolated Sites feature in Google Chrome before 26.0.1410.43 does not properly enforce the use of
The Isolated Sites feature in Google Chrome before 26.0.1410.43 does not properly enforce the use of separate processes, which makes it easier for remote attackers to bypass intended access restrictions via a crafted web site.
nvd
CVE-2013-2632MEDIUMCVSS 6.8≤ 27.0.1444.02013-03-21
CVE-2013-2632 [MEDIUM] CVE-2013-2632: Google V8 before 3.17.13, as used in Google Chrome before 27.0.1444.3, allows remote attackers to ca
Google V8 before 3.17.13, as used in Google Chrome before 27.0.1444.3, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code, as demonstrated by the Bejeweled game.
nvd
CVE-2013-0912HIGHCVSS 7.5v25.0.1364.0v25.0.1364.1+109 more2013-03-11
CVE-2013-0912 [HIGH] CWE-94 CVE-2013-0912: WebKit in Google Chrome before 25.0.1364.160 allows remote attackers to execute arbitrary code via v
WebKit in Google Chrome before 25.0.1364.160 allows remote attackers to execute arbitrary code via vectors that leverage "type confusion."
nvd
CVE-2013-0910HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0910 [HIGH] CWE-287 CVE-2013-0910: Google Chrome before 25.0.1364.152 does not properly manage the interaction between the browser proc
Google Chrome before 25.0.1364.152 does not properly manage the interaction between the browser process and renderer processes during authorization of the loading of a plug-in, which makes it easier for remote attackers to bypass intended access restrictions via vectors involving a blocked plug-in.
nvd
CVE-2013-0903HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0903 [HIGH] CWE-399 CVE-2013-0903: Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause
Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of browser navigation.
nvd