Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82
Vulnerabilities
Page 17 of 292
CVE-2026-10954P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10954 [HIGH] CWE-416 CVE-2026-10954: Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute
Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10902P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10902 [HIGH] CWE-416 CVE-2026-10902: Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute
Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10895P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10895 [HIGH] CWE-416 CVE-2026-10895: Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute
Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-10956P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10956 [HIGH] CWE-416 CVE-2026-10956: Use after free in MimeHandlerView in Google Chrome prior to 149.0.7827.53 allowed a remote attacker
Use after free in MimeHandlerView in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11118P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11118 [HIGH] CWE-416 CVE-2026-11118: Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9952P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9952 [HIGH] CWE-416 CVE-2026-9952: Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to exe
Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5873P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5873 [HIGH] CWE-125 CVE-2026-5873: Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker
Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13965P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13965 [HIGH] CWE-416 CVE-2026-13965: Use after free in Oilpan in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execut
Use after free in Oilpan in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-6301P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6301 [HIGH] CWE-843 CVE-2026-6301: Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to exe
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-6303P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6303 [HIGH] CWE-416 CVE-2026-6303: Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execu
Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-6307P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6307 [HIGH] CWE-843 CVE-2026-6307: Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to exe
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13888P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13888 [HIGH] CWE-416 CVE-2026-13888: Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to ex
Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13845P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13845 [HIGH] CWE-416 CVE-2026-13845: Use after free in DOM in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute a
Use after free in DOM in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13811P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13811 [HIGH] CWE-416 CVE-2026-13811: Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute a
Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13848P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13848 [HIGH] CWE-416 CVE-2026-13848: Use after free in Forms in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute
Use after free in Forms in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13821P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13821 [HIGH] CWE-416 CVE-2026-13821: Use after free in Canvas in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execut
Use after free in Canvas in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10991P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10991 [HIGH] CWE-416 CVE-2026-10991: Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced
Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10957P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10957 [HIGH] CWE-416 CVE-2026-10957: Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute
Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11046P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11046 [HIGH] CWE-20 CVE-2026-11046: Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed
Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11028P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11028 [HIGH] CWE-416 CVE-2026-11028: Use after free in Media in Google Chrome on Linux and ChromeOS prior to 149.0.7827.53 allowed a remo
Use after free in Media in Google Chrome on Linux and ChromeOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd