Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 188 of 292
CVE-2013-2844P4HIGHCVSS 7.5≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2844 [HIGH] CWE-399 CVE-2013-2844: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome bef
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to style resolution.
nvd
CVE-2013-2841P4HIGHCVSS 7.5≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2841 [HIGH] CWE-399 CVE-2013-2841: Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of Pepper resources.
nvd
CVE-2013-0903P4HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0903 [HIGH] CWE-399 CVE-2013-0903: Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause
Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of browser navigation.
nvd
CVE-2013-0902P4HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0902 [HIGH] CWE-399 CVE-2013-0902: Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 25.0.1364.15
Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-0905P4HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0905 [HIGH] CWE-399 CVE-2013-0905: Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause
Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an SVG animation.
nvd
CVE-2012-5147P4HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2012-5147 [HIGH] CWE-399 CVE-2012-5147: Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOM handling.
nvd
CVE-2013-0832P4HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0832 [HIGH] CWE-399 CVE-2013-0832: Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.
nvd
CVE-2012-5150P4HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2012-5150 [HIGH] CWE-399 CVE-2012-5150: Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving seek operations on video data.
nvd
CVE-2016-1690P4HIGHCVSS 7.5≤ 50.0.2661.1022016-06-05
CVE-2016-1690 [HIGH] CVE-2016-1690: The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between
The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.
nvd
CVE-2010-4202P4CRITICALCVSS 9.8fixed in 7.0.517.442010-11-06
CVE-2010-4202 [CRITICAL] CWE-190 CVE-2010-4202: Multiple integer overflows in Google Chrome before 7.0.517.44 on Linux allow remote attackers to cau
Multiple integer overflows in Google Chrome before 7.0.517.44 on Linux allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font.
nvd
CVE-2012-2880P4HIGHCVSS 7.5≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2880 [HIGH] CWE-362 CVE-2012-2880: Race condition in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of ser
Race condition in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the plug-in paint buffer.
nvd
CVE-2010-3416P4CRITICALCVSS 9.8fixed in 6.0.472.592010-09-16
CVE-2010-3416 [CRITICAL] CWE-119 CVE-2010-3416: Google Chrome before 6.0.472.59 on Linux does not properly implement the Khmer locale, which allows
Google Chrome before 6.0.472.59 on Linux does not properly implement the Khmer locale, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-3333P4HIGHCVSS 7.5≤ 42.0.2311.602015-04-19
CVE-2015-3333 [HIGH] CVE-2015-3333: Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2026-7950P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7950 [MEDIUM] CWE-125 CVE-2026-7950: Out of bounds read and write in GFX in Google Chrome prior to 148.0.7778.96 allowed a remote attacke
Out of bounds read and write in GFX in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform arbitrary read/write via malicious network traffic. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2015-3910P4HIGHCVSS 7.5≤ 42.0.2311.1522015-05-20
CVE-2015-3910 [HIGH] CVE-2015-3910: Multiple unspecified vulnerabilities in Google V8 before 4.3.61.21, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.3.61.21, as used in Google Chrome before 43.0.2357.65, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2013-0919P4HIGHCVSS 7.5≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0919 [HIGH] CWE-399 CVE-2013-0919: Use-after-free vulnerability in Google Chrome before 26.0.1410.43 on Linux allows remote attackers t
Use-after-free vulnerability in Google Chrome before 26.0.1410.43 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging the presence of an extension that creates a pop-up window.
nvd
CVE-2015-7834P4HIGHCVSS 7.5≤ 45.0.2454.1012015-10-15
CVE-2015-7834 [HIGH] CVE-2015-7834: Multiple unspecified vulnerabilities in Google V8 before 4.6.85.23, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.6.85.23, as used in Google Chrome before 46.0.2490.71, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2014-3161P4HIGHCVSS 7.5≤ 36.0.1985.106v36.0.1985.1+98 more2014-07-20
CVE-2014-3161 [HIGH] CWE-264 CVE-2014-3161: The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc
The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly interact with redirects, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that hosts a video stream.
nvd
CVE-2013-2268P4HIGHCVSS 7.5≤ 25.0.1364.95v25.0.1364.0+87 more2013-02-23
CVE-2013-2268 [HIGH] CVE-2013-2268: Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.9
Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue."
nvd
CVE-2010-4035P4CRITICALCVSS 9.3≤ 7.0.517.40v6.0.454.0+177 more2010-10-21
CVE-2010-4035 [CRITICAL] CWE-20 CVE-2010-4035: Google Chrome before 7.0.517.41 does not properly perform autofill operations for forms, which allow
Google Chrome before 7.0.517.41 does not properly perform autofill operations for forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.
nvd