Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 179 of 292
CVE-2009-2556P4CRITICALCVSS 9.3≤ 2.0.172.33v0.2.149.29+26 more2009-07-21
CVE-2009-2556 [CRITICAL] CWE-119 CVE-2009-2556: Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of se
Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger excessive memory allocation.
nvd
CVE-2016-5173P4HIGHCVSS 7.1≤ 53.0.2785.1012016-09-25
CVE-2016-5173 [HIGH] CWE-284 CVE-2016-5173: The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass the Same Origin Policy via an indirect interception attack.
nvd
CVE-2012-2875P4MEDIUMCVSS 6.8≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2875 [MEDIUM] CVE-2012-2875: Multiple unspecified vulnerabilities in the PDF functionality in Google Chrome before 22.0.1229.79 a
Multiple unspecified vulnerabilities in the PDF functionality in Google Chrome before 22.0.1229.79 allow remote attackers to have an unknown impact via a crafted document.
nvd
CVE-2015-1273P4MEDIUMCVSS 6.8≤ 43.0.2357.1342015-07-23
CVE-2015-1273 [MEDIUM] CWE-119 CVE-2015-1273: Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome bef
Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid JPEG2000 data in a PDF document.
nvd
CVE-2017-15396P4MEDIUMCVSS 6.5fixed in 62.0.3202.752018-08-28
CVE-2017-15396 [MEDIUM] CWE-119 CVE-2017-15396: A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ b
A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2011-2819P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2819 [MEDIUM] CVE-2011-2819: Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vecto
Google Chrome before 13.0.782.107 allows remote attackers to bypass the Same Origin Policy via vectors related to handling of the base URI.
nvd
CVE-2011-3873P4MEDIUMCVSS 6.8fixed in 14.0.835.2022011-10-04
CVE-2011-3873 [MEDIUM] CWE-119 CVE-2011-3873: Google Chrome before 14.0.835.202 does not properly implement shader translation, which allows remot
Google Chrome before 14.0.835.202 does not properly implement shader translation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2011-3056P4MEDIUMCVSS 6.8fixed in 17.0.963.832012-03-22
CVE-2011-3056 [MEDIUM] CWE-346 CVE-2011-3056: Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vector
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
nvd
CVE-2019-13751P4MEDIUMCVSS 6.5fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13751 [MEDIUM] CWE-908 CVE-2019-13751: Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obt
Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2020-6395P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6395 [MEDIUM] CWE-125 CVE-2020-6395: Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to
Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2020-6397P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6397 [MEDIUM] CVE-2020-6397: Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote atta
Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2018-6123P4MEDIUMCVSS 6.5fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6123 [MEDIUM] CWE-416 CVE-2018-6123: A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potent
A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-5172P4MEDIUMCVSS 6.5≤ 53.0.2785.1012016-09-25
CVE-2016-5172 [MEDIUM] CWE-200 CVE-2016-5172: The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which all
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
nvd
CVE-2018-16078P4MEDIUMCVSS 6.5fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16078 [MEDIUM] CWE-200 CVE-2018-16078: Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a
Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2016-1665P4MEDIUMCVSS 6.5≤ 50.0.2661.872016-05-14
CVE-2016-1665 [MEDIUM] CWE-20 CVE-2016-1665: The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrom
The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sensitive information via crafted JavaScript code.
nvd
CVE-2020-6558P4MEDIUMCVSS 6.5fixed in 85.0.4183.83≥ unspecified, < 85.0.4183.832020-09-21
CVE-2020-6558 [MEDIUM] CWE-79 CVE-2020-6558: Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a re
Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6473P4MEDIUMCVSS 6.5fixed in 83.0.4103.61≥ unspecified, < 83.0.4103.612020-05-21
CVE-2020-6473 [MEDIUM] CWE-203 CVE-2020-6473: Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote att
Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2017-15415P4MEDIUMCVSS 6.5fixed in 63.0.3239.842018-08-28
CVE-2017-15415 [MEDIUM] CWE-119 CVE-2017-15415: Incorrect serialization in IPC in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to l
Incorrect serialization in IPC in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the value of a pointer via a crafted HTML page.
nvd
CVE-2020-6526P4MEDIUMCVSS 6.5fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6526 [MEDIUM] CVE-2020-6526: Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remo
Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2017-5117P4MEDIUMCVSS 6.5fixed in 61.0.3163.792017-10-27
CVE-2017-5117 [MEDIUM] CWE-200 CVE-2017-5117: Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Linux and Windows a
Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Linux and Windows allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd