Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 182 of 292
CVE-2019-5767P4MEDIUMCVSS 6.5fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5767 [MEDIUM] CWE-1021 CVE-2019-5767: Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.8
Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.
nvd
CVE-2021-30534P4MEDIUMCVSS 6.5fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30534 [MEDIUM] CWE-863 CVE-2021-30534: Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a re
Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2016-5201P4MEDIUMCVSS 6.5≤ 54.0.2840.872017-01-19
CVE-2016-5201 [MEDIUM] CWE-200 CVE-2016-5201: A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and
A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and 54.0.2840.99 for Windows, and 54.0.2840.98 for Mac allowed a remote attacker to access privileged JavaScript code via a crafted HTML page.
nvd
CVE-2021-4054P4MEDIUMCVSS 6.5fixed in 96.0.4664.93≥ unspecified, < 96.0.4664.932021-12-23
CVE-2021-4054 [MEDIUM] CVE-2021-4054: Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker t
Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2024-4559P4MEDIUMCVSS 6.5fixed in 124.0.6367.155≥ 124.0.6367.155, < 124.0.6367.1552024-05-07
CVE-2024-4559 [MEDIUM] CWE-787 CVE-2024-4559: Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker
Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-3516P4MEDIUMCVSS 6.5fixed in 123.0.6312.122≥ 123.0.6312.122, < 123.0.6312.1222024-04-10
CVE-2024-3516 [MEDIUM] CWE-787 CVE-2024-3516: Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to
Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-0792P4MEDIUMCVSS 6.5fixed in 99.0.4844.51≥ unspecified, < 99.0.4844.512022-04-05
CVE-2022-0792 [MEDIUM] CWE-125 CVE-2022-0792: Out of bounds read in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to pote
Out of bounds read in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-1817P4MEDIUMCVSS 6.5fixed in 112.0.5615.49≥ 112.0.5615.49, < 112.0.5615.492023-04-04
CVE-2023-1817 [MEDIUM] CVE-2023-1817: Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowe
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1822P4MEDIUMCVSS 6.5fixed in 112.0.5615.49≥ 112.0.5615.49, < 112.0.5615.492023-04-04
CVE-2023-1822 [MEDIUM] CVE-2023-1822: Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacke
Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2022-3056P4MEDIUMCVSS 6.5fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3056 [MEDIUM] CWE-693 CVE-2022-3056: Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 a
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2024-4059P4MEDIUMCVSS 6.5fixed in 124.0.6367.78≥ 124.0.6367.78, < 124.0.6367.782024-05-01
CVE-2024-4059 [MEDIUM] CWE-125 CVE-2024-4059: Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to le
Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-1823P4MEDIUMCVSS 6.5fixed in 112.0.5615.49≥ 112.0.5615.49, < 112.0.5615.492023-04-04
CVE-2023-1823 [MEDIUM] CVE-2023-1823: Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attac
Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-0704P4MEDIUMCVSS 6.5fixed in 110.0.5481.77≥ unspecified, < 110.0.5481.772023-02-07
CVE-2023-0704 [MEDIUM] CWE-602 CVE-2023-0704: Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote
Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-1819P4MEDIUMCVSS 6.5fixed in 112.0.5615.49≥ 112.0.5615.49, < 112.0.5615.492023-04-04
CVE-2023-1819 [MEDIUM] CWE-125 CVE-2023-1819: Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacke
Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-1139P4MEDIUMCVSS 6.5fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1139 [MEDIUM] CWE-203 CVE-2022-1139: Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed
Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2026-17919P4MEDIUMCVSS 6.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17919 [MEDIUM] CWE-693 CVE-2026-17919: Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed
Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security severity: Low)
nvd
CVE-2022-1138P4MEDIUMCVSS 6.5fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1138 [MEDIUM] CWE-1021 CVE-2022-1138: Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote
Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had compromised the renderer process to obscure the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2022-1482P4MEDIUMCVSS 6.5fixed in 101.0.4951.41≥ unspecified, < 101.0.4951.412022-07-26
CVE-2022-1482 [MEDIUM] CWE-787 CVE-2022-1482: Inappropriate implementation in WebGL in Google Chrome prior to 101.0.4951.41 allowed a remote attac
Inappropriate implementation in WebGL in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6444P4MEDIUMCVSS 6.3fixed in 81.0.4044.92≥ unspecified, < 81.0.4044.922020-04-13
CVE-2020-6444 [MEDIUM] CWE-908 CVE-2020-6444: Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to pote
Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-1816P4MEDIUMCVSS 6.5fixed in 112.0.5615.49≥ 112.0.5615.49, < 112.0.5615.492023-04-04
CVE-2023-1816 [MEDIUM] CVE-2023-1816: Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote
Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd