Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82
Vulnerabilities
Page 20 of 292
CVE-2026-11000P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11000 [HIGH] CWE-416 CVE-2026-11000: Use after free in Fonts in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker t
Use after free in Fonts in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10945P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10945 [HIGH] CWE-416 CVE-2026-10945: Use after free in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convince
Use after free in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
nvd
CVE-2026-11662P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11662 [HIGH] CWE-843 CVE-2026-11662: Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to exe
Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11068P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11068 [HIGH] CWE-416 CVE-2026-11068: Use after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to ex
Use after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11054P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11054 [HIGH] CWE-416 CVE-2026-11054: Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9962P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9962 [HIGH] CWE-416 CVE-2026-9962: Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execu
Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17705P3HIGHCVSS 8.8≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17705 [HIGH] CWE-190 CVE-2026-17705: Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to exec
Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-4447P3HIGHCVSS 8.8fixed in 146.0.7680.153≥ 146.0.7680.153, < 146.0.7680.1532026-03-20
CVE-2026-4447 [HIGH] CWE-693 CVE-2026-4447: Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacke
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-15776P3HIGHCVSS 8.8fixed in 150.0.7871.125≥ 150.0.7871.125, < 150.0.7871.1252026-07-14
CVE-2026-15776 [HIGH] CWE-843 CVE-2026-15776: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacke
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14383P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14383 [HIGH] CWE-94 CVE-2026-14383: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7902P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7902 [HIGH] CWE-787 CVE-2026-7902: Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker
Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7337P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7337 [HIGH] CWE-843 CVE-2026-7337: Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute a
Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-16421P3HIGHCVSS 8.8fixed in 150.0.7871.182≥ 150.0.7871.182, < 150.0.7871.1822026-07-21
CVE-2026-16421 [HIGH] CWE-20 CVE-2026-16421: Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote a
Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-6300P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6300 [HIGH] CWE-416 CVE-2026-6300: Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute
Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5279P3HIGHCVSS 8.8fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5279 [HIGH] CWE-120 CVE-2026-5279: Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execut
Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7980P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7980 [HIGH] CWE-416 CVE-2026-7980: Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to exec
Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7987P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7987 [HIGH] CWE-416 CVE-2026-7987: Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execut
Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7928P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7928 [HIGH] CWE-416 CVE-2026-7928: Use after free in WebRTC in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacke
Use after free in WebRTC in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-6318P3HIGHCVSS 8.8fixed in 147.0.7727.101≥ 147.0.7727.101, < 147.0.7727.1012026-04-15
CVE-2026-6318 [HIGH] CWE-416 CVE-2026-6318: Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execu
Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5871P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5871 [HIGH] CWE-843 CVE-2026-5871: Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute ar
Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd