cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 183 of 292
CVE-2023-1821P4MEDIUMCVSS 6.5fixed in 112.0.5615.49≥ 112.0.5615.49, < 112.0.5615.492023-04-04
CVE-2023-1821 [MEDIUM] CVE-2023-1821: Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote at Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4350P4MEDIUMCVSS 6.5fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4350 [MEDIUM] CVE-2023-4350: Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowe Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2016-5176P4MEDIUMCVSS 6.5≤ 53.0.2785.1012016-09-29
CVE-2016-5176 [MEDIUM] CWE-284 CVE-2016-5176: Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mec Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecified vectors.
nvd
CVE-2020-6569P4MEDIUMCVSS 6.3fixed in 85.0.4183.83≥ unspecified, < 85.0.4183.832020-09-21
CVE-2020-6569 [MEDIUM] CWE-190 CVE-2020-6569: Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0120P4MEDIUMCVSS 6.5fixed in 97.0.4692.71≥ unspecified, < 97.0.4692.712022-02-12
CVE-2022-0120 [MEDIUM] CWE-346 CVE-2022-0120: Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote at Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially leak cross-origin data via a malicious website.
nvd
CVE-2022-1500P4MEDIUMCVSS 6.5fixed in 101.0.4951.41≥ unspecified, < 101.0.4951.412022-07-26
CVE-2022-1500 [MEDIUM] CWE-20 CVE-2022-1500: Insufficient data validation in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote a Insufficient data validation in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2022-0291P4MEDIUMCVSS 6.5fixed in 97.0.4692.99≥ unspecified, < 97.0.4692.992022-02-12
CVE-2022-0291 [MEDIUM] CVE-2022-0291: Inappropriate implementation in Storage in Google Chrome prior to 97.0.4692.99 allowed a remote atta Inappropriate implementation in Storage in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2013-0829P4MEDIUMCVSS 6.4≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0829 [MEDIUM] CWE-264 CVE-2013-0829: Google Chrome before 24.0.1312.52 does not properly maintain database metadata, which allows remote Google Chrome before 24.0.1312.52 does not properly maintain database metadata, which allows remote attackers to bypass intended file-access restrictions via unspecified vectors.
nvd
CVE-2024-3839P4MEDIUMCVSS 6.5fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-04-17
CVE-2024-3839 [MEDIUM] CWE-125 CVE-2024-3839: Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obt Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-1128P4MEDIUMCVSS 6.5fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1128 [MEDIUM] CWE-22 CVE-2022-1128: Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 all Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.
nvd
CVE-2023-0700P4MEDIUMCVSS 6.5fixed in 110.0.5481.77≥ unspecified, < 110.0.5481.772023-02-07
CVE-2023-0700 [MEDIUM] CWE-451 CVE-2023-0700: Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote at Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-3313P4MEDIUMCVSS 6.5fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3313 [MEDIUM] CWE-451 CVE-2022-3313: Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attack Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-3054P4MEDIUMCVSS 6.5fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3054 [MEDIUM] CVE-2022-3054: Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2605P4MEDIUMCVSS 6.5fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2605 [MEDIUM] CWE-125 CVE-2022-2605: Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to pote Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-4187P4MEDIUMCVSS 6.5fixed in 108.0.5359.71≥ unspecified, < 108.0.5359.712022-11-30
CVE-2022-4187 [MEDIUM] CVE-2022-4187: Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 108.0.5359.71 allow Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 108.0.5359.71 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-0131P4MEDIUMCVSS 6.5fixed in 109.0.5414.74≥ unspecified, < 109.0.5414.742023-01-10
CVE-2023-0131 [MEDIUM] CWE-693 CVE-2023-0131: Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to bypass file download restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4913P4MEDIUMCVSS 6.5fixed in 105.0.5195.52≥ 105.0.5195.52, < 105.0.5195.522023-07-29
CVE-2022-4913 [MEDIUM] CVE-2022-4913: Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to spoof extension storage via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-0140P4MEDIUMCVSS 6.5fixed in 109.0.5414.74≥ unspecified, < 109.0.5414.742023-01-10
CVE-2023-0140 [MEDIUM] CVE-2023-0140: Inappropriate implementation in in File System API in Google Chrome on Windows prior to 109.0.5414.7 Inappropriate implementation in in File System API in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2022-2622P4MEDIUMCVSS 6.5fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2622 [MEDIUM] CVE-2022-2622: Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104 Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file.
nvd
CVE-2022-4922P4MEDIUMCVSS 6.5fixed in 99.0.4844.51≥ 99.0.4844.51, < 99.0.4844.512023-07-29
CVE-2022-4922 [MEDIUM] CVE-2022-4922: Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attack Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase