cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 185 of 292
CVE-2022-4909P4MEDIUMCVSS 6.3fixed in 107.0.5304.62≥ 107.0.5304.62, < 107.0.5304.622023-07-29
CVE-2022-4909 [MEDIUM] CVE-2022-4909: Inappropriate implementation in XML in Google Chrome prior to 107.0.5304.62 allowed a remote attacke Inappropriate implementation in XML in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially perform an ASLR bypass via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-1235P4MEDIUMCVSS 6.3fixed in 111.0.5563.64≥ 111.0.5563.64, < 111.0.5563.642023-03-07
CVE-2023-1235 [MEDIUM] CWE-843 CVE-2023-1235: Type confusion in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had Type confusion in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted UI interaction. (Chromium security severity: Low)
nvd
CVE-2026-7971P4MEDIUMCVSS 6.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7971 [MEDIUM] CWE-269 CVE-2026-7971: Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacke Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11181P4MEDIUMCVSS 6.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11181 [MEDIUM] CWE-346 CVE-2026-11181: Inappropriate implementation in Media Session in Google Chrome prior to 149.0.7827.53 allowed a remo Inappropriate implementation in Media Session in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11238P4MEDIUMCVSS 5.9fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11238 [MEDIUM] CWE-306 CVE-2026-11238: Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2025-12436P4MEDIUMCVSS 5.9fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12436 [MEDIUM] CWE-306 CVE-2025-12436: Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convince Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2010-4040P4HIGHCVSS 7.8fixed in 7.0.517.412010-10-21
CVE-2010-4040 [HIGH] CWE-20 CVE-2010-4040: Google Chrome before 7.0.517.41 does not properly handle animated GIF images, which allows remote at Google Chrome before 7.0.517.41 does not properly handle animated GIF images, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted image.
nvd
CVE-2015-6771P4HIGHCVSS 7.5≤ 46.0.2490.862015-12-06
CVE-2015-6771 [HIGH] CWE-119 CVE-2015-6771: js/array.js in Google V8, as used in Google Chrome before 47.0.2526.73, improperly implements certai js/array.js in Google V8, as used in Google Chrome before 47.0.2526.73, improperly implements certain map and filter operations for arrays, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2011-1121P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1121 [HIGH] CWE-190 CVE-2011-1121: Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of se Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a TEXTAREA element.
nvd
CVE-2026-17736P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17736 [MEDIUM] CWE-20 CVE-2026-17736: Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.792 Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17746P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17746 [MEDIUM] CWE-416 CVE-2026-17746: Use after free in GPU in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who h Use after free in GPU in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17745P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17745 [MEDIUM] CWE-125 CVE-2026-17745: Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17776P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17776 [MEDIUM] CWE-693 CVE-2026-17776: Policy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had Policy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17893P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17893 [MEDIUM] CWE-20 CVE-2026-17893: Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17890P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17890 [MEDIUM] CWE-20 CVE-2026-17890: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allow Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2012-2869P4HIGHCVSS 7.5≤ 21.0.1180.88v21.0.1180.0+50 more2012-08-31
CVE-2012-2869 [HIGH] CWE-119 CVE-2012-2869: Google Chrome before 21.0.1180.89 does not properly load URLs, which allows remote attackers to caus Google Chrome before 21.0.1180.89 does not properly load URLs, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a "stale buffer."
nvd
CVE-2026-17809P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17809 [MEDIUM] CWE-20 CVE-2026-17809: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 all Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17806P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17806 [MEDIUM] CWE-20 CVE-2026-17806: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 all Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-1188P4HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1188 [HIGH] CVE-2011-1188: Google Chrome before 10.0.648.127 does not properly handle counter nodes, which allows remote attack Google Chrome before 10.0.648.127 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-2827P4HIGHCVSS 7.5fixed in 13.0.782.2152011-08-29
CVE-2011-2827 [HIGH] CWE-416 CVE-2011-2827: Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to text searching.
nvd
Google Chrome vulnerabilities | cvebase