cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 170 of 292
CVE-2023-1814P4MEDIUMCVSS 6.5fixed in 112.0.5615.49≥ 112.0.5615.49, < 112.0.5615.492023-04-04
CVE-2023-1814 [MEDIUM] CVE-2023-1814: Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2016-5171P4HIGHCVSS 8.8≤ 53.0.2785.1012016-09-25
CVE-2016-5171 [HIGH] CWE-416 CVE-2016-5171: WebKit/Source/bindings/templates/interface.cpp in Blink, as used in Google Chrome before 53.0.2785.1 WebKit/Source/bindings/templates/interface.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not prevent certain constructor calls, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-7395P4HIGHCVSS 8.8≤ 52.0.2743.1162016-09-11
CVE-2016-7395 [HIGH] CWE-19 CVE-2016-7395: SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0 SkPath.cpp in Skia, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, does not properly validate the return values of ChopMonoAtY calls, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via crafted graph
nvd
CVE-2022-1867P4MEDIUMCVSS 6.5fixed in 102.0.5005.61≥ unspecified, < 102.0.5005.612022-07-27
CVE-2022-1867 [MEDIUM] CVE-2022-1867: Insufficient validation of untrusted input in Data Transfer in Google Chrome prior to 102.0.5005.61 Insufficient validation of untrusted input in Data Transfer in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to bypass same origin policy via a crafted clipboard content.
nvd
CVE-2023-5483P4MEDIUMCVSS 6.5fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5483 [MEDIUM] CVE-2023-5483: Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote att Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5481P4MEDIUMCVSS 6.5fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5481 [MEDIUM] CVE-2023-5481: Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote a Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-2630P4MEDIUMCVSS 6.5fixed in 123.0.6312.58≥ 123.0.6312.58, < 123.0.6312.582024-03-20
CVE-2024-2630 [MEDIUM] CWE-79 CVE-2024-2630: Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacke Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-1671P4MEDIUMCVSS 6.5fixed in 122.0.6261.57≥ 122.0.6261.57, < 122.0.6261.572024-02-21
CVE-2024-1671 [MEDIUM] CWE-693 CVE-2024-1671: Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a rem Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1813P4MEDIUMCVSS 6.5fixed in 112.0.5615.49≥ 112.0.5615.49, < 112.0.5615.492023-04-04
CVE-2023-1813 [MEDIUM] CVE-2023-1813: Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attack Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-2940P4MEDIUMCVSS 6.5fixed in 114.0.5735.90≥ 114.0.5735.90, < 114.0.5735.902023-05-30
CVE-2023-2940 [MEDIUM] CWE-284 CVE-2023-2940: Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacke Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5487P4MEDIUMCVSS 6.5fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5487 [MEDIUM] CVE-2023-5487: Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attack Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2023-5479P4MEDIUMCVSS 6.5fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5479 [MEDIUM] CVE-2023-5479: Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an at Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-2618P4MEDIUMCVSS 6.5fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2618 [MEDIUM] CWE-20 CVE-2022-2618: Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allo Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a malicious file .
nvd
CVE-2023-4367P4MEDIUMCVSS 6.5fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4367 [MEDIUM] CVE-2023-4367: Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-3311P4MEDIUMCVSS 6.5fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3311 [MEDIUM] CWE-416 CVE-2022-3311: Use after free in import in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had c Use after free in import in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4911P4MEDIUMCVSS 6.5fixed in 106.0.5249.62≥ 106.0.5249.62, < 106.0.5249.622023-07-29
CVE-2022-4911 [MEDIUM] CWE-20 CVE-2022-4911: Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote at Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2022-2861P4MEDIUMCVSS 6.5fixed in 104.0.5112.101≥ unspecified, < 104.0.5112.1012022-09-26
CVE-2022-2861 [MEDIUM] CWE-79 CVE-2022-2861: Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an a Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page.
nvd
CVE-2023-0139P4MEDIUMCVSS 6.5fixed in 109.0.5414.74≥ unspecified, < 109.0.5414.742023-01-10
CVE-2023-0139 [MEDIUM] CWE-20 CVE-2023-0139: Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5 Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass download restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-2311P4MEDIUMCVSS 6.5fixed in 112.0.5615.49≥ 112.0.5615.49, < 112.0.5615.492023-07-29
CVE-2023-2311 [MEDIUM] CVE-2023-2311: Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-1868P4MEDIUMCVSS 6.5fixed in 102.0.5005.61≥ unspecified, < 102.0.5005.612022-07-27
CVE-2022-1868 [MEDIUM] CVE-2022-1868: Inappropriate implementation in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an at Inappropriate implementation in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase