cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 194 of 292
CVE-2022-1858P4MEDIUMCVSS 6.5fixed in 102.0.5005.61≥ unspecified, < 102.0.5005.612022-07-27
CVE-2022-1858 [MEDIUM] CWE-125 CVE-2022-1858: Out of bounds read in DevTools in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to Out of bounds read in DevTools in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform an out of bounds memory read via specific user interaction.
nvd
CVE-2022-0294P4MEDIUMCVSS 6.5fixed in 97.0.4692.99≥ unspecified, < 97.0.4692.992022-02-12
CVE-2022-0294 [MEDIUM] CVE-2022-0294: Inappropriate implementation in Push messaging in Google Chrome prior to 97.0.4692.99 allowed a remo Inappropriate implementation in Push messaging in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2019-13662P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13662 [MEDIUM] CWE-276 CVE-2019-13662: Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.3865.75 allowed a remo Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2022-2610P4MEDIUMCVSS 6.5fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2610 [MEDIUM] CWE-668 CVE-2022-2610: Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-2160P4MEDIUMCVSS 6.5fixed in 103.0.5060.53≥ unspecified, < 103.0.5060.532022-07-28
CVE-2022-2160 [MEDIUM] CWE-362 CVE-2022-2160: Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allow Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML page.
nvd
CVE-2022-2612P4MEDIUMCVSS 6.5fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2612 [MEDIUM] CWE-203 CVE-2022-2612: Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2022-0292P4MEDIUMCVSS 6.5fixed in 97.0.4692.99≥ unspecified, < 97.0.4692.992022-02-12
CVE-2022-0292 [MEDIUM] CVE-2022-0292: Inappropriate implementation in Fenced Frames in Google Chrome prior to 97.0.4692.99 allowed a remot Inappropriate implementation in Fenced Frames in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2018-17460P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-17460 [MEDIUM] CWE-20 CVE-2018-17460: Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a rem Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2022-2615P4MEDIUMCVSS 6.5fixed in 104.0.5112.79≥ unspecified, < 104.0.5112.792022-08-12
CVE-2022-2615 [MEDIUM] CWE-565 CVE-2022-2615: Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-0305P4MEDIUMCVSS 6.5fixed in 97.0.4692.99≥ unspecified, < 97.0.4692.992022-02-12
CVE-2022-0305 [MEDIUM] CVE-2022-0305: Inappropriate implementation in Service Worker API in Google Chrome prior to 97.0.4692.99 allowed a Inappropriate implementation in Service Worker API in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2022-1137P4MEDIUMCVSS 6.5fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1137 [MEDIUM] CWE-668 CVE-2022-1137: Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attack Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to leak potentially sensitive information via a crafted HTML page.
nvd
CVE-2018-6125P4MEDIUMCVSS 6.5fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622021-11-02
CVE-2018-6125 [MEDIUM] CVE-2018-6125: Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a r Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.
nvd
CVE-2022-4915P4MEDIUMCVSS 6.5fixed in 103.0.5060.134≥ 103.0.5060.134, < 103.0.5060.1342023-07-29
CVE-2022-4915 [MEDIUM] CVE-2022-4915: Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5060.134 allowed a re Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2019-5879P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-5879 [MEDIUM] CWE-863 CVE-2019-5879: Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an atta Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.
nvd
CVE-2023-0133P4MEDIUMCVSS 6.5fixed in 109.0.5414.74≥ unspecified, < 109.0.5414.742023-01-10
CVE-2023-0133 [MEDIUM] CWE-863 CVE-2023-0133: Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.541 Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main origin permission delegation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-4926P4MEDIUMCVSS 6.5fixed in 109.0.5414.119≥ 109.0.5414.119, < 109.0.5414.1192023-07-29
CVE-2022-4926 [MEDIUM] CWE-522 CVE-2022-4926: Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allow Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-0130P4MEDIUMCVSS 6.5fixed in 109.0.5414.74≥ unspecified, < 109.0.5414.742023-01-10
CVE-2023-0130 [MEDIUM] CWE-451 CVE-2023-0130: Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-0697P4MEDIUMCVSS 6.5fixed in 110.0.5481.77≥ unspecified, < 110.0.5481.772023-02-07
CVE-2023-0697 [MEDIUM] CVE-2023-0697: Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-0441P4MEDIUMCVSS 6.5fixed in 132.0.6834.83≥ 132.0.6834.83, < 132.0.6834.832025-01-15
CVE-2025-0441 [MEDIUM] CWE-200 CVE-2025-0441: Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remo Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtain potentially sensitive information from the system via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-1921P4MEDIUMCVSS 6.5fixed in 134.0.6998.35≥ 134.0.6998.35, < 134.0.6998.352025-03-05
CVE-2025-1921 [MEDIUM] CWE-1230 CVE-2025-1921: Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remot Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about a peripheral via a crafted HTML page. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase