cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 164 of 292
CVE-2025-11208P4MEDIUMCVSS 6.3fixed in 141.0.7390.54≥ 141.0.7390.54, < 141.0.7390.542025-11-06
CVE-2025-11208 [MEDIUM] CWE-451 CVE-2025-11208: Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attac Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-11212P4MEDIUMCVSS 6.3fixed in 141.0.7390.54≥ 141.0.7390.54, < 141.0.7390.542025-11-06
CVE-2025-11212 [MEDIUM] CWE-451 CVE-2025-11212: Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a r Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8010P4MEDIUMCVSS 6.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8010 [MEDIUM] CWE-20 CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11308P4MEDIUMCVSS 6.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11308 [MEDIUM] CWE-269 CVE-2026-11308: Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attack Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2015-1242P4HIGHCVSS 7.5≤ 42.0.2311.602015-04-19
CVE-2015-1242 [HIGH] CVE-2015-1242: The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.7 The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.
nvd
CVE-2011-0471P4CRITICALCVSS 10.0fixed in 8.0.552.2372011-01-14
CVE-2011-0471 [CRITICAL] CWE-20 CVE-2011-0471: The node-iteration implementation in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.3 The node-iteration implementation in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 does not properly handle pointers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-2882P4HIGHCVSS 7.5≤ 28.0.1500.94v28.0.1500.0+67 more2013-07-31
CVE-2013-2882 [HIGH] CWE-843 CVE-2013-2882: Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial o Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
nvd
CVE-2013-0892P4HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0892 [HIGH] CVE-2013-0892: Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Window Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2014-7926P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7926 [HIGH] CWE-17 CVE-2014-7926: The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier.
nvd
CVE-2014-7923P4HIGHCVSS 7.5≤ 40.0.2214.852015-01-22
CVE-2014-7923 [HIGH] CWE-17 CVE-2014-7923: The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a look-behind expression.
nvd
CVE-2015-1284P4HIGHCVSS 7.5≤ 43.0.2357.1342015-07-23
CVE-2015-1284 [HIGH] CWE-20 CVE-2015-1284: The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrom The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly check for a page's maximum number of frames, which allows remote attackers to cause a denial of service (invalid count value and use-after-free) or possibly have unspecified other impact via crafted JavaScript code
nvd
CVE-2015-1217P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1217 [HIGH] CWE-17 CVE-2015-1217: The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
nvd
CVE-2015-1230P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-1230 [HIGH] CVE-2015-1230: The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that adds an AudioContext event listener and triggers "type conf
nvd
CVE-2015-6775P4HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-6775 [HIGH] CVE-2015-6775: fpdfsdk/src/jsapi/fxjs_v8.cpp in PDFium, as used in Google Chrome before 47.0.2526.73, does not use fpdfsdk/src/jsapi/fxjs_v8.cpp in PDFium, as used in Google Chrome before 47.0.2526.73, does not use signatures, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
nvd
CVE-2011-3090P4HIGHCVSS 7.6≤ 19.0.1084.452012-05-16
CVE-2011-3090 [HIGH] CWE-362 CVE-2011-3090: Race condition in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of ser Race condition in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to worker processes.
nvd
CVE-2011-3101P4CRITICALCVSS 10.0≤ 19.0.1084.452012-05-16
CVE-2011-3101 [CRITICAL] CVE-2011-3101: Google Chrome before 19.0.1084.46 on Linux does not properly mitigate an unspecified flaw in an NVID Google Chrome before 19.0.1084.46 on Linux does not properly mitigate an unspecified flaw in an NVIDIA driver, which has unknown impact and attack vectors. NOTE: see CVE-2012-3105 for the related MFSA 2012-34 issue in Mozilla products.
nvd
CVE-2013-6650P4HIGHCVSS 7.5≤ 32.0.1700.101v32.0.1700.0+67 more2014-01-28
CVE-2013-6650 [HIGH] CWE-20 CVE-2013-6650: The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as u The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors that trigger incorrect handling of "popular pages."
nvd
CVE-2010-3114P4CRITICALCVSS 10.0fixed in 5.0.375.1272010-08-24
CVE-2010-3114 [CRITICAL] CVE-2010-3114: The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, doe The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLineBreakCommand.cpp, or (3) InsertParagraphSeparatorCommand.cpp in WebCore/editing/.
nvd
CVE-2011-3021P4HIGHCVSS 7.5fixed in 17.0.963.562012-02-16
CVE-2011-3021 [HIGH] CWE-416 CVE-2011-3021: Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to subframe loading.
nvd
CVE-2011-3922P4HIGHCVSS 7.5fixed in 16.0.912.752012-01-07
CVE-2011-3922 [HIGH] CWE-787 CVE-2011-3922: Stack-based buffer overflow in Google Chrome before 16.0.912.75 allows remote attackers to cause a d Stack-based buffer overflow in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to glyph handling.
nvd
Google Chrome vulnerabilities | cvebase