cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82

Vulnerabilities

Page 18 of 292
CVE-2026-7336P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7336 [HIGH] CWE-416 CVE-2026-7336: Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execu Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10910P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10910 [HIGH] CWE-843 CVE-2026-10910: Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute ar Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4680P3HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4680 [HIGH] CWE-416 CVE-2026-4680: Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execut Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10941P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10941 [HIGH] CWE-125 CVE-2026-10941: Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacke Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5287P3HIGHCVSS 8.8fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5287 [HIGH] CWE-416 CVE-2026-5287: Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
nvd
CVE-2026-13898P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13898 [HIGH] CWE-416 CVE-2026-13898: Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10904P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10904 [HIGH] CWE-20 CVE-2026-10904: Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10928P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10928 [HIGH] CWE-94 CVE-2026-10928: Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to ex Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5285P3HIGHCVSS 8.8fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5285 [HIGH] CWE-416 CVE-2026-5285: Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execut Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7341P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7341 [HIGH] CWE-416 CVE-2026-7341: Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execu Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14067P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14067 [HIGH] CWE-416 CVE-2026-14067: Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote att Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-4678P3HIGHCVSS 8.8fixed in 146.0.7680.164≥ 146.0.7680.165, < 146.0.7680.1652026-03-24
CVE-2026-4678 [HIGH] CWE-416 CVE-2026-4678: Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execu Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9126P3HIGHCVSS 8.8fixed in 148.0.7778.178≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9126 [HIGH] CWE-416 CVE-2026-9126: Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execu Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5280P3HIGHCVSS 8.8fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5280 [HIGH] CWE-416 CVE-2026-5280: Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to ex Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10936P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10936 [HIGH] CWE-843 CVE-2026-10936: Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute ar Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10962P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10962 [HIGH] CWE-843 CVE-2026-10962: Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10935P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10935 [HIGH] CWE-843 CVE-2026-10935: Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute ar Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13786P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13786 [HIGH] CWE-416 CVE-2026-13786: Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-13815P3HIGHCVSS 8.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13815 [HIGH] CWE-416 CVE-2026-13815: Use after free in Blink in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute Use after free in Blink in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-10954P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10954 [HIGH] CWE-416 CVE-2026-10954: Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase