cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 172 of 292
CVE-2026-14035P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14035 [MEDIUM] CWE-284 CVE-2026-14035: Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remot Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14061P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14061 [MEDIUM] CWE-284 CVE-2026-14061: Inappropriate implementation in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attack Inappropriate implementation in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11206P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11206 [MEDIUM] CWE-693 CVE-2026-11206: Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed a r Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11160P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11160 [MEDIUM] CWE-125 CVE-2026-11160: Out of bounds read in Input in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attack Out of bounds read in Input in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-2316P4MEDIUMCVSS 6.5fixed in 145.0.7632.45≥ 145.0.7632.45, < 145.0.7632.452026-02-11
CVE-2026-2316 [MEDIUM] CWE-451 CVE-2026-2316: Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote a Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14399P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14399 [MEDIUM] CWE-457 CVE-2026-14399: Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtai Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14408P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14408 [MEDIUM] CWE-457 CVE-2026-14408: Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtai Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14402P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14402 [MEDIUM] CWE-457 CVE-2026-14402: Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attac Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10008P4MEDIUMCVSS 6.5fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-10008 [MEDIUM] CWE-457 CVE-2026-10008: Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attack Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-15768P4MEDIUMCVSS 6.5fixed in 150.0.7871.125≥ 150.0.7871.125, < 150.0.7871.1252026-07-14
CVE-2026-15768 [MEDIUM] CWE-346 CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14148P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14148 [MEDIUM] CWE-843 CVE-2026-14148: Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain po Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-13996P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13996 [MEDIUM] CWE-451 CVE-2026-13996: Inappropriate implementation in Permissions in Google Chrome prior to 150.0.7871.47 allowed a remote Inappropriate implementation in Permissions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-15109P4MEDIUMCVSS 6.5fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15109 [MEDIUM] CWE-457 CVE-2026-15109: Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obt Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14421P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14421 [MEDIUM] CWE-457 CVE-2026-14421: Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attac Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14015P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14015 [MEDIUM] CWE-362 CVE-2026-14015: Race in WebRTC in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to leak Race in WebRTC in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11275P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11275 [MEDIUM] CWE-284 CVE-2026-11275: Inappropriate implementation in Page Info in Google Chrome on Android prior to 149.0.7827.53 allowed Inappropriate implementation in Page Info in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11204P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11204 [MEDIUM] CWE-284 CVE-2026-11204: Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remo Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5283P4MEDIUMCVSS 6.5fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5283 [MEDIUM] CWE-285 CVE-2026-5283: Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote atta Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-2317P4MEDIUMCVSS 6.5fixed in 145.0.7632.45≥ 145.0.7632.45, < 145.0.7632.452026-02-11
CVE-2026-2317 [MEDIUM] CWE-200 CVE-2026-2317: Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote a Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11289P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11289 [MEDIUM] CWE-1300 CVE-2026-11289: Side-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote a Side-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
Google Chrome vulnerabilities | cvebase