Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 198 of 292
CVE-2012-2823P4HIGHCVSS 7.5≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2823 [HIGH] CWE-399 CVE-2012-2823: Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG resources.
nvd
CVE-2011-1794P4HIGHCVSS 7.5≤ 11.0.696.642014-12-26
CVE-2011-1794 [HIGH] CWE-189 CVE-2011-1794: Integer overflow in the FilterEffect::copyImageBytes function in platform/graphics/filters/FilterEff
Integer overflow in the FilterEffect::copyImageBytes function in platform/graphics/filters/FilterEffect.cpp in the SVG filter implementation in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted dimensions.
nvd
CVE-2013-0916P4HIGHCVSS 7.5≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0916 [HIGH] CWE-399 CVE-2013-0916: Use-after-free vulnerability in the Web Audio implementation in Google Chrome before 26.0.1410.43 al
Use-after-free vulnerability in the Web Audio implementation in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-0906P4HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0906 [HIGH] CWE-119 CVE-2013-0906: The IndexedDB implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause
The IndexedDB implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3917P4HIGHCVSS 7.5fixed in 16.0.912.632011-12-13
CVE-2011-3917 [HIGH] CWE-787 CVE-2011-3917: Stack-based buffer overflow in FileWatcher in Google Chrome before 16.0.912.63 allows remote attacke
Stack-based buffer overflow in FileWatcher in Google Chrome before 16.0.912.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-0898P4HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0898 [HIGH] CWE-416 CVE-2013-0898: Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 2
Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a URL.
nvd
CVE-2011-3904P4HIGHCVSS 7.5fixed in 16.0.912.632011-12-13
CVE-2011-3904 [HIGH] CWE-416 CVE-2011-3904: Use-after-free vulnerability in Google Chrome before 16.0.912.63 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 16.0.912.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to bidirectional text (aka bidi) handling.
nvd
CVE-2010-1228P4CRITICALCVSS 10.0≤ 4.1.249.1035v0.2.149.27+82 more2010-04-01
CVE-2010-1228 [CRITICAL] CWE-362 CVE-2010-1228: Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have uns
Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have unspecified impact and attack vectors.
nvd
CVE-2026-17799P4MEDIUMCVSS 5.4fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17799 [MEDIUM] CWE-20 CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.0.7922.72
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-7962P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7962 [MEDIUM] CWE-20 CVE-2026-7962: Insufficient policy enforcement in DirectSockets in Google Chrome prior to 148.0.7778.96 allowed a r
Insufficient policy enforcement in DirectSockets in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform arbitrary read/write via a crafted Chrome Extension. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2013-0885P4HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0885 [HIGH] CWE-732 CVE-2013-0885: Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does no
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack vectors.
nvd
CVE-2011-2862P4HIGHCVSS 7.5fixed in 14.0.835.1632011-09-19
CVE-2011-2862 [HIGH] CWE-264 CVE-2011-2862: Google V8, as used in Google Chrome before 14.0.835.163, does not properly restrict access to built-
Google V8, as used in Google Chrome before 14.0.835.163, does not properly restrict access to built-in objects, which has unspecified impact and remote attack vectors.
nvd
CVE-2013-0887P4HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0887 [HIGH] CWE-732 CVE-2013-0887: The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25
The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict privileges during interaction with a connected server, which has unspecified impact and attack vectors.
nvd
CVE-2013-2867P4HIGHCVSS 7.5≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2867 [HIGH] CVE-2013-2867: Google Chrome before 28.0.1500.71 does not properly prevent pop-under windows, which allows remote a
Google Chrome before 28.0.1500.71 does not properly prevent pop-under windows, which allows remote attackers to have an unspecified impact via a crafted web site.
nvd
CVE-2010-2110P4HIGHCVSS 7.5fixed in 5.0.375.552010-05-28
CVE-2010-2110 [HIGH] CVE-2010-2110: Google Chrome before 5.0.375.55 does not properly execute JavaScript code in the extension context,
Google Chrome before 5.0.375.55 does not properly execute JavaScript code in the extension context, which has unspecified impact and remote attack vectors.
nvd
CVE-2026-17909P4MEDIUMCVSS 5.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17909 [MEDIUM] CWE-20 CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922
Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2011-0472P4CRITICALCVSS 9.3fixed in 8.0.552.2372011-01-14
CVE-2011-0472 [CRITICAL] CVE-2011-0472: Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle the printin
Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle the printing of PDF documents, which allows user-assisted remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a multi-page document.
nvd
CVE-2014-1745P4HIGHCVSS 7.1≤ 35.0.1916.113v35.0.1916.0+78 more2014-05-21
CVE-2014-1745 [HIGH] CWE-399 CVE-2014-1745: Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger removal of an SVGFontFaceElement object, related to core/svg/SVGFontFaceElement.cpp.
nvd
CVE-2015-2238P4HIGHCVSS 7.5≤ 40.0.2214.1152015-03-09
CVE-2015-2238 [HIGH] CVE-2015-2238: Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 4
Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2015-6580P4HIGHCVSS 7.5≤ 44.0.24032015-09-03
CVE-2015-6580 [HIGH] CVE-2015-6580: Multiple unspecified vulnerabilities in Google V8 before 4.5.103.29, as used in Google Chrome before
Multiple unspecified vulnerabilities in Google V8 before 4.5.103.29, as used in Google Chrome before 45.0.2454.85, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd