Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 202 of 292
CVE-2021-21211P4MEDIUMCVSS 6.5fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21211 [MEDIUM] CWE-346 CVE-2021-21211: Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a r
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6538P4MEDIUMCVSS 6.5fixed in 84.0.4147.105≥ unspecified, < 84.0.4147.1052020-09-21
CVE-2020-6538 [MEDIUM] CVE-2020-6538: Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a
Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5793P4MEDIUMCVSS 6.5fixed in 73.0.3683.75vprior to 73.0.3683.752019-05-23
CVE-2019-5793 [MEDIUM] CWE-20 CVE-2019-5793: Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remot
Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installation user interface via a crafted HTML page.
nvd
CVE-2019-13722P4MEDIUMCVSS 6.5fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792020-01-14
CVE-2019-13722 [MEDIUM] CWE-787 CVE-2019-13722: Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attac
Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-5207P4MEDIUMCVSS 6.1≤ 54.0.2840.992017-01-19
CVE-2016-5207 [MEDIUM] CWE-79 CVE-2016-5207: In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for And
In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android, corruption of the DOM tree could occur during the removal of a full screen element, which allowed a remote attacker to achieve arbitrary code execution via a crafted HTML page.
nvd
CVE-2019-13709P4MEDIUMCVSS 6.5fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13709 [MEDIUM] CWE-290 CVE-2019-13709: Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote
Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
nvd
CVE-2026-11628P4MEDIUMCVSS 6.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11628 [MEDIUM] CWE-416 CVE-2026-11628: Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potenti
Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: Critical)
nvd
CVE-2019-13670P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13670 [MEDIUM] CWE-787 CVE-2019-13670: Insufficient data validation in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote a
Insufficient data validation in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5814P4MEDIUMCVSS 6.5fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5814 [MEDIUM] CWE-352 CVE-2019-5814: Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote at
Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2026-13282P4MEDIUMCVSS 6.8fixed in 149.0.7827.201≥ 149.0.7827.201, < 149.0.7827.2012026-06-25
CVE-2026-13282 [MEDIUM] CWE-416 CVE-2026-13282: Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attac
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)
nvd
CVE-2021-38010P4MEDIUMCVSS 6.5fixed in 96.0.4664.45≥ unspecified, < 96.0.4664.452021-12-23
CVE-2021-38010 [MEDIUM] CVE-2021-38010: Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a rem
Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2020-16042P4MEDIUMCVSS 6.5fixed in 87.0.4280.88≥ unspecified, < 87.0.4280.882021-01-08
CVE-2020-16042 [MEDIUM] CWE-908 CVE-2020-16042: Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain p
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2022-0802P4MEDIUMCVSS 6.5fixed in 99.0.4844.51≥ unspecified, < 99.0.4844.512022-04-05
CVE-2022-0802 [MEDIUM] CVE-2022-0802: Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 a
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2022-0804P4MEDIUMCVSS 6.5fixed in 99.0.4844.51≥ unspecified, < 99.0.4844.512022-04-05
CVE-2022-0804 [MEDIUM] CVE-2022-0804: Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 a
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2020-6498P4MEDIUMCVSS 6.5fixed in 83.0.4103.88≥ unspecified, < 83.0.4103.882020-06-03
CVE-2020-6498 [MEDIUM] CWE-276 CVE-2020-6498: Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a r
Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2019-13683P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13683 [MEDIUM] CWE-755 CVE-2019-13683: Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a
Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-16073P4MEDIUMCVSS 6.5fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-06-27
CVE-2018-16073 [MEDIUM] CWE-285 CVE-2018-16073: Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a r
Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.
nvd
CVE-2018-6150P4MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172019-06-27
CVE-2018-6150 [MEDIUM] CWE-200 CVE-2018-6150: Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote
Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-16074P4MEDIUMCVSS 6.5fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-06-27
CVE-2018-16074 [MEDIUM] CWE-285 CVE-2018-16074: Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a r
Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.
nvd
CVE-2021-21229P4MEDIUMCVSS 6.5fixed in 90.0.4430.93≥ unspecified, < 90.0.4430.932021-04-30
CVE-2021-21229 [MEDIUM] CWE-346 CVE-2021-21229: Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remot
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd