Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 191 of 292
CVE-2019-5846P4MEDIUMCVSS 6.5fixed in 73.0.3683.75≥ unspecified, < 73.0.3683.752020-01-03
CVE-2019-5846 [MEDIUM] CWE-787 CVE-2019-5846: Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5845P4MEDIUMCVSS 6.5fixed in 73.0.3683.75≥ unspecified, < 73.0.3683.752020-01-03
CVE-2019-5845 [MEDIUM] CWE-787 CVE-2019-5845: Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5830P4MEDIUMCVSS 6.5fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5830 [MEDIUM] CVE-2019-5830: Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote atta
Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5812P4MEDIUMCVSS 6.5fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5812 [MEDIUM] CVE-2019-5812: Inadequate security UI in iOS UI in Google Chrome prior to 74.0.3729.108 allowed a remote attacker t
Inadequate security UI in iOS UI in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2020-15982P4MEDIUMCVSS 6.5fixed in 86.0.4240.75≥ unspecified, < 86.0.4240.752020-11-03
CVE-2020-15982 [MEDIUM] CVE-2020-15982: Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attack
Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2016-1699P4MEDIUMCVSS 6.5≤ 51.0.2704.632016-06-05
CVE-2016-1699 [MEDIUM] CWE-284 CVE-2016-1699: WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blin
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL.
nvd
CVE-2019-13737P4MEDIUMCVSS 6.5fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13737 [MEDIUM] CWE-200 CVE-2019-13737: Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a rem
Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2018-18350P4MEDIUMCVSS 6.5fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18350 [MEDIUM] CVE-2018-18350: Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.357
Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2019-13746P4MEDIUMCVSS 6.5fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13746 [MEDIUM] CVE-2019-13746: Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote a
Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-6169P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6169 [MEDIUM] CWE-20 CVE-2018-6169: Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 all
Lack of timeout on extension install prompt in Extensions in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to trigger installation of an unwanted extension via a crafted HTML page.
nvd
CVE-2021-30580P4MEDIUMCVSS 6.5fixed in 92.0.4515.107≥ unspecified, < 92.0.4515.1072021-08-03
CVE-2021-30580 [MEDIUM] CVE-2021-30580: Insufficient policy enforcement in Android intents in Google Chrome prior to 92.0.4515.107 allowed a
Insufficient policy enforcement in Android intents in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious application to obtain potentially sensitive information via a crafted HTML page.
nvd
CVE-2016-1618P4MEDIUMCVSS 6.5≤ 47.0.2526.1062016-01-25
CVE-2016-1618 [MEDIUM] CWE-200 CVE-2016-1618: Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographically
Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
nvd
CVE-2020-6482P4MEDIUMCVSS 6.5fixed in 83.0.4103.61≥ unspecified, < 83.0.4103.612020-05-21
CVE-2020-6482 [MEDIUM] CWE-276 CVE-2020-6482: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2020-15986P4MEDIUMCVSS 6.5fixed in 86.0.4240.75≥ unspecified, < 86.0.4240.752020-11-03
CVE-2020-15986 [MEDIUM] CWE-190 CVE-2020-15986: Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potent
Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0109P4MEDIUMCVSS 6.5fixed in 97.0.4692.71≥ unspecified, < 97.0.4692.712022-02-12
CVE-2022-0109 [MEDIUM] CVE-2022-0109: Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote att
Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.
nvd
CVE-2017-15391P4MEDIUMCVSS 6.5fixed in 62.0.3202.622018-02-07
CVE-2017-15391 [MEDIUM] CVE-2017-15391: Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remot
Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to access Extension pages without authorisation via a crafted HTML page.
nvd
CVE-2016-5212P4MEDIUMCVSS 6.5≤ 54.0.2840.992017-01-19
CVE-2016-5212 [MEDIUM] CWE-200 CVE-2016-5212: Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android insuffi
Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android insufficiently sanitized DevTools URLs, which allowed a remote attacker to read local files via a crafted HTML page.
nvd
CVE-2019-13738P4MEDIUMCVSS 6.5fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13738 [MEDIUM] CWE-269 CVE-2019-13738: Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remot
Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted HTML page.
nvd
CVE-2017-15419P4MEDIUMCVSS 6.5fixed in 63.0.3239.842018-08-28
CVE-2017-15419 [MEDIUM] CWE-601 CVE-2017-15419: Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowe
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.
nvd
CVE-2019-13743P4MEDIUMCVSS 6.5fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13743 [MEDIUM] CVE-2019-13743: Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a
Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd