cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 195 of 292
CVE-2022-1499P4MEDIUMCVSS 6.3fixed in 101.0.4951.41≥ unspecified, < 101.0.4951.412022-07-26
CVE-2022-1499 [MEDIUM] CWE-863 CVE-2022-1499: Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2026-13879P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13879 [MEDIUM] CWE-416 CVE-2026-13879: Use after free in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local Use after free in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (Chromium security severity: Medium)
nvd
CVE-2026-13940P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13940 [MEDIUM] CWE-457 CVE-2026-13940: Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local n Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Medium)
nvd
CVE-2026-14119P4MEDIUMCVSS 6.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14119 [MEDIUM] CWE-843 CVE-2026-14119: Type Confusion in Bluetooth in Google Chrome on Windows prior to 150.0.7871.47 allowed an attacker o Type Confusion in Bluetooth in Google Chrome on Windows prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (Chromium security severity: Low)
nvd
CVE-2025-14372P4MEDIUMCVSS 6.1fixed in 143.0.7499.109≥ 143.0.7499.110, < 143.0.7499.1102025-12-12
CVE-2025-14372 [MEDIUM] CWE-416 CVE-2025-14372: Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacke Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5896P4MEDIUMCVSS 6.1fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5896 [MEDIUM] CWE-693 CVE-2026-5896: Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinc Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass sandbox download restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2012-2816P4HIGHCVSS 7.8≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2816 [HIGH] CVE-2012-2816: Google Chrome before 20.0.1132.43 on Windows does not properly isolate sandboxed processes, which mi Google Chrome before 20.0.1132.43 on Windows does not properly isolate sandboxed processes, which might allow remote attackers to cause a denial of service (process interference) via unspecified vectors.
nvd
CVE-2011-0983P4HIGHCVSS 7.5fixed in 9.0.597.942011-02-10
CVE-2011-0983 [HIGH] CWE-20 CVE-2011-0983: Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attac Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-0981P4HIGHCVSS 7.5fixed in 9.0.597.942011-02-10
CVE-2011-0981 [HIGH] CWE-20 CVE-2011-0981: Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allow Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-2821P4HIGHCVSS 7.5fixed in 13.0.782.2152011-08-29
CVE-2011-2821 [HIGH] CWE-415 CVE-2011-2821: Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote at Double free vulnerability in libxml2, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted XPath expression.
nvd
CVE-2026-17866P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17866 [MEDIUM] CWE-843 CVE-2026-17866: Type Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker w Type Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17770P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17770 [MEDIUM] CWE-125 CVE-2026-17770: Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17891P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17891 [MEDIUM] CWE-416 CVE-2026-17891: Use after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker Use after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17906P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17906 [MEDIUM] CWE-20 CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allo Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17908P4MEDIUMCVSS 5.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17908 [MEDIUM] CWE-20 CVE-2026-17908: Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.79 Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2011-0484P4HIGHCVSS 7.5fixed in 8.0.552.2372011-01-14
CVE-2011-0484 [HIGH] CWE-20 CVE-2011-0484: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform DOM node r Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform DOM node removal, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale rendering node."
nvd
CVE-2011-1203P4HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1203 [HIGH] CVE-2011-1203: Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attacker Google Chrome before 10.0.648.127 does not properly handle SVG cursors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1109P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1109 [HIGH] CWE-20 CVE-2011-1109: Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) sty Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets (CSS) stylesheets, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1291P4HIGHCVSS 7.5fixed in 10.0.648.2042011-03-25
CVE-2011-1291 [HIGH] CWE-120 CVE-2011-1291: Google Chrome before 10.0.648.204 does not properly handle base strings, which allows remote attacke Google Chrome before 10.0.648.204 does not properly handle base strings, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "buffer error."
nvd
CVE-2010-3119P4CRITICALCVSS 10.0fixed in 5.0.375.1272010-08-24
CVE-2010-3119 [CRITICAL] CWE-119 CVE-2010-3119: Google Chrome before 5.0.375.127 and webkitgtk before 1.2.6 do not properly support the Ruby languag Google Chrome before 5.0.375.127 and webkitgtk before 1.2.6 do not properly support the Ruby language, which allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
Google Chrome vulnerabilities | cvebase