Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 171 of 292
CVE-2022-4925P4MEDIUMCVSS 6.5fixed in 97.0.4692.71≥ 97.0.4692.71, < 97.0.4692.712023-07-29
CVE-2022-4925 [MEDIUM] CWE-20 CVE-2022-4925: Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a
Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform header splitting via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2024-5840P4MEDIUMCVSS 6.5fixed in 126.0.6478.54≥ 126.0.6478.54, < 126.0.6478.542024-06-11
CVE-2024-5840 [MEDIUM] CWE-284 CVE-2024-5840: Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass di
Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-5066P4MEDIUMCVSS 6.5fixed in 137.0.7151.55≥ 137.0.7151.55, < 137.0.7151.552025-05-27
CVE-2025-5066 [MEDIUM] CWE-451 CVE-2025-5066: Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed
Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-0442P4MEDIUMCVSS 6.5fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0442 [MEDIUM] CWE-290 CVE-2025-0442: Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote at
Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4955P4MEDIUMCVSS 6.5fixed in 108.0.5359.71≥ 108.0.5359.71, < 108.0.5359.712023-08-04
CVE-2022-4955 [MEDIUM] CVE-2022-4955: Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker
Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14074P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14074 [MEDIUM] CWE-1300 CVE-2026-14074: Side-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47
Side-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-9917P4MEDIUMCVSS 6.5fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9917 [MEDIUM] CWE-457 CVE-2026-9917: Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote atta
Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5888P4MEDIUMCVSS 6.5fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5888 [MEDIUM] CWE-457 CVE-2026-5888: Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to
Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14008P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14008 [MEDIUM] CWE-457 CVE-2026-14008: Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attac
Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11067P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11067 [MEDIUM] CWE-457 CVE-2026-11067: Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtai
Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11033P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11033 [MEDIUM] CWE-457 CVE-2026-11033: Uninitialized Use in WebML in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker
Uninitialized Use in WebML in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11137P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11137 [MEDIUM] CWE-457 CVE-2026-11137: Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obta
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11123P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11123 [MEDIUM] CWE-457 CVE-2026-11123: Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obta
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8570P4MEDIUMCVSS 6.5fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8570 [MEDIUM] CWE-843 CVE-2026-8570: Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain po
Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9912P4MEDIUMCVSS 6.5fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9912 [MEDIUM] CWE-200 CVE-2026-9912: Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a re
Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7924P4MEDIUMCVSS 6.5fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7924 [MEDIUM] CWE-457 CVE-2026-7924: Uninitialized Use in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtai
Uninitialized Use in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7982P4MEDIUMCVSS 6.5fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7982 [MEDIUM] CWE-457 CVE-2026-7982: Uninitialized Use in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to
Uninitialized Use in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-8881P4MEDIUMCVSS 6.5fixed in 139.0.7258.127≥ 139.0.7258.127, < 139.0.7258.1272025-08-13
CVE-2025-8881 [MEDIUM] CWE-303 CVE-2025-8881: Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remot
Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14396P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14396 [MEDIUM] CWE-125 CVE-2026-14396: Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to lea
Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13949P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13949 [MEDIUM] CWE-284 CVE-2026-13949: Insufficient policy enforcement in Payments in Google Chrome on Android prior to 150.0.7871.47 allow
Insufficient policy enforcement in Payments in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd