Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 184 of 292
CVE-2022-1862P4MEDIUMCVSS 6.5fixed in 102.0.5005.61≥ unspecified, < 102.0.5005.612022-07-27
CVE-2022-1862 [MEDIUM] CVE-2022-1862: Inappropriate implementation in Extensions in Google Chrome prior to 102.0.5005.61 allowed an attack
Inappropriate implementation in Extensions in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass profile restrictions via a crafted HTML page.
nvd
CVE-2023-1217P4MEDIUMCVSS 6.5fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1217 [MEDIUM] CWE-787 CVE-2023-1217: Stack buffer overflow in Crash reporting in Google Chrome on Windows prior to 111.0.5563.64 allowed
Stack buffer overflow in Crash reporting in Google Chrome on Windows prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-0132P4MEDIUMCVSS 6.5fixed in 109.0.5414.74≥ unspecified, < 109.0.5414.742023-01-10
CVE-2023-0132 [MEDIUM] CWE-346 CVE-2023-0132: Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.541
Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to force acceptance of a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2018-16064P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-16064 [MEDIUM] CWE-20 CVE-2018-16064: Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an att
Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2022-3047P4MEDIUMCVSS 6.5fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3047 [MEDIUM] CWE-602 CVE-2022-3047: Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an
Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page.
nvd
CVE-2023-1226P4MEDIUMCVSS 6.5fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1226 [MEDIUM] CVE-2023-1226: Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed
Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-3314P4MEDIUMCVSS 6.5fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3314 [MEDIUM] CWE-416 CVE-2022-3314: Use after free in logging in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had
Use after free in logging in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-0440P4MEDIUMCVSS 6.5fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0440 [MEDIUM] CWE-290 CVE-2025-0440: Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowe
Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-7011P4MEDIUMCVSS 6.5fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052024-07-16
CVE-2023-7011 [MEDIUM] CWE-451 CVE-2023-7011: Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed
Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-2616P4MEDIUMCVSS 6.5fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2616 [MEDIUM] CVE-2022-2616: Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an at
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to spoof the contents of the Omnibox (URL bar) via a crafted Chrome Extension.
nvd
CVE-2023-2314P4MEDIUMCVSS 6.5fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-07-29
CVE-2023-2314 [MEDIUM] CWE-345 CVE-2023-2314: Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote at
Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-0435P4MEDIUMCVSS 6.5fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0435 [MEDIUM] CWE-451 CVE-2025-0435: Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowe
Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6777P4MEDIUMCVSS 6.5fixed in 126.0.6478.182≥ 126.0.6478.182, < 126.0.6478.1822024-07-16
CVE-2024-6777 [MEDIUM] CWE-416 CVE-2024-6777: Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convin
Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2024-0814P4MEDIUMCVSS 6.5fixed in 121.0.6167.85≥ 121.0.6167.85, < 121.0.6167.852024-01-24
CVE-2024-0814 [MEDIUM] CWE-346 CVE-2024-0814: Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker
Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2020-36765P4MEDIUMCVSS 6.5fixed in 85.0.4183.83≥ 85.0.4183.83, < 85.0.4183.832024-07-16
CVE-2020-36765 [MEDIUM] CVE-2020-36765: Insufficient policy enforcement in Navigation in Google Chrome prior to 85.0.4183.83 allowed a remot
Insufficient policy enforcement in Navigation in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-11110P4MEDIUMCVSS 6.5fixed in 131.0.6778.69≥ 131.0.6778.69, < 131.0.6778.692024-11-12
CVE-2024-11110 [MEDIUM] CWE-79 CVE-2024-11110: Inappropriate implementation in Extensions in Google Chrome prior to 131.0.6778.69 allowed a remote
Inappropriate implementation in Extensions in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2024-5500P4MEDIUMCVSS 6.5fixed in 122.0.6261.57≥ 122.0.6261.57, < 122.0.6261.572024-07-16
CVE-2024-5500 [MEDIUM] CWE-358 CVE-2024-5500: Inappropriate implementation in Sign-In in Google Chrome prior to 1.3.36.351 allowed a remote attack
Inappropriate implementation in Sign-In in Google Chrome prior to 1.3.36.351 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-0439P4MEDIUMCVSS 6.5fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0439 [MEDIUM] CWE-362 CVE-2025-0439: Race in Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a use
Race in Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-2884P4MEDIUMCVSS 6.5fixed in 121.0.6167.139≥ 121.0.6167.139, < 121.0.6167.1392024-07-16
CVE-2024-2884 [MEDIUM] CWE-125 CVE-2024-2884: Out of bounds read in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to poten
Out of bounds read in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11215P4MEDIUMCVSS 6.5fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11215 [MEDIUM] CWE-451 CVE-2026-11215: Inappropriate implementation in Cronet in Google Chrome on Android prior to 149.0.7827.53 allowed a
Inappropriate implementation in Cronet in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
nvd