Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 190 of 292
CVE-2020-6562P4MEDIUMCVSS 6.5fixed in 85.0.4183.83≥ unspecified, < 85.0.4183.832020-09-21
CVE-2020-6562 [MEDIUM] CWE-79 CVE-2020-6562: Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote att
Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6103P4MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172018-12-04
CVE-2018-6103 [MEDIUM] CVE-2018-6103: A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote att
A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass permission policy via a crafted HTML page.
nvd
CVE-2017-5011P4MEDIUMCVSS 6.5≤ 55.0.2883.872017-02-17
CVE-2017-5011 [MEDIUM] CWE-200 CVE-2017-5011: Google Chrome prior to 56.0.2924.76 for Windows insufficiently sanitized DevTools URLs, which allowe
Google Chrome prior to 56.0.2924.76 for Windows insufficiently sanitized DevTools URLs, which allowed a remote attacker who convinced a user to install a malicious extension to read filesystem contents via a crafted HTML page.
nvd
CVE-2020-6565P4MEDIUMCVSS 6.5fixed in 85.0.4183.83≥ unspecified, < 85.0.4183.832020-09-21
CVE-2020-6565 [MEDIUM] CVE-2020-6565: Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remo
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2020-6494P4MEDIUMCVSS 6.5fixed in 83.0.4103.97≥ unspecified, < 83.0.4103.972020-06-03
CVE-2020-6494 [MEDIUM] CVE-2020-6494: Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote
Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2020-6472P4MEDIUMCVSS 6.5fixed in 83.0.4103.61≥ unspecified, < 83.0.4103.612020-05-21
CVE-2020-6472 [MEDIUM] CVE-2020-6472: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory or disk via a crafted Chrome Extension.
nvd
CVE-2018-6166P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6166 [MEDIUM] CVE-2018-6166: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6114P4MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-01-09
CVE-2018-6114 [MEDIUM] CWE-20 CVE-2018-6114: Incorrect enforcement of CSP for <object> tags in Blink in Google Chrome prior to 66.0.3359.117 allo
Incorrect enforcement of CSP for tags in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2018-6098P4MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172018-12-04
CVE-2018-6098 [MEDIUM] CVE-2018-6098: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2016-1687P4MEDIUMCVSS 6.5≤ 50.0.2661.1022016-06-05
CVE-2016-1687 [MEDIUM] CWE-200 CVE-2016-1687: The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public e
The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers to obtain sensitive information via vectors related to extensions.
nvd
CVE-2019-13744P4MEDIUMCVSS 6.5fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13744 [MEDIUM] CWE-200 CVE-2019-13744: Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote a
Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6133P4MEDIUMCVSS 6.5fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6133 [MEDIUM] CWE-19 CVE-2018-6133: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 67.0.3396.62
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6032P4MEDIUMCVSS 6.5fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6032 [MEDIUM] CWE-20 CVE-2018-6032: Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote at
Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted HTML page.
nvd
CVE-2018-6175P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6175 [MEDIUM] CVE-2018-6175: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6163P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6163 [MEDIUM] CVE-2018-6163: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6167P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6167 [MEDIUM] CVE-2018-6167: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6172P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6172 [MEDIUM] CVE-2018-6172: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6173P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6173 [MEDIUM] CVE-2018-6173: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2018-6040P4MEDIUMCVSS 6.5fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6040 [MEDIUM] CWE-732 CVE-2018-6040: Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote at
Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially bypass content security policy via a crafted HTML page.
nvd
CVE-2019-5844P4MEDIUMCVSS 6.5fixed in 73.0.3683.75≥ unspecified, < 73.0.3683.752020-01-03
CVE-2019-5844 [MEDIUM] CWE-787 CVE-2019-5844: Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd