cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 203 of 292
CVE-2019-5847P4MEDIUMCVSS 6.5fixed in 75.0.3770.142≥ unspecified, < 75.0.3770.1422019-11-25
CVE-2019-5847 [MEDIUM] CWE-787 CVE-2019-5847: Inappropriate implementation in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote Inappropriate implementation in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13740P4MEDIUMCVSS 6.5fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13740 [MEDIUM] CWE-346 CVE-2019-13740: Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2019-13677P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13677 [MEDIUM] CWE-732 CVE-2019-13677: Insufficient policy enforcement in site isolation in Google Chrome prior to 77.0.3865.75 allowed a r Insufficient policy enforcement in site isolation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.
nvd
CVE-2020-6497P4MEDIUMCVSS 6.5fixed in 83.0.4103.88≥ unspecified, < 83.0.4103.882020-06-03
CVE-2020-6497 [MEDIUM] CWE-276 CVE-2020-6497: Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a r Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted URI.
nvd
CVE-2022-1129P4MEDIUMCVSS 6.5fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1129 [MEDIUM] CWE-290 CVE-2022-1129: Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2021-38021P4MEDIUMCVSS 6.5fixed in 96.0.4664.45≥ unspecified, < 96.0.4664.452021-12-23
CVE-2021-38021 [MEDIUM] CVE-2021-38021: Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote att Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2021-37995P4MEDIUMCVSS 6.5fixed in 95.0.4638.54≥ unspecified, < 95.0.4638.542021-11-02
CVE-2021-37995 [MEDIUM] CVE-2021-37995: Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a re Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2021-38018P4MEDIUMCVSS 6.5fixed in 96.0.4664.45≥ unspecified, < 96.0.4664.452021-12-23
CVE-2021-38018 [MEDIUM] CVE-2021-38018: Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote a Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2018-16072P4MEDIUMCVSS 6.5fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-01-09
CVE-2018-16072 [MEDIUM] CWE-346 CVE-2018-16072: A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allo A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2019-13697P4MEDIUMCVSS 6.5fixed in 77.0.3865.120≥ unspecified, < 77.0.3865.1202019-11-25
CVE-2019-13697 [MEDIUM] CWE-209 CVE-2019-13697: Insufficient policy enforcement in performance APIs in Google Chrome prior to 77.0.3865.120 allowed Insufficient policy enforcement in performance APIs in Google Chrome prior to 77.0.3865.120 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5869P4MEDIUMCVSS 6.5fixed in 76.0.3809.132≥ unspecified, < 76.0.3809.1322019-11-25
CVE-2019-5869 [MEDIUM] CWE-416 CVE-2019-5869: Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote attacker to potenti Use after free in Blink in Google Chrome prior to 76.0.3809.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-6136P4MEDIUMCVSS 6.5fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-06-27
CVE-2018-6136 [MEDIUM] CWE-125 CVE-2018-6136: Missing type check in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform Missing type check in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2020-16036P4MEDIUMCVSS 6.5fixed in 87.0.4280.66≥ unspecified, < 87.0.4280.662021-01-08
CVE-2020-16036 [MEDIUM] CVE-2020-16036: Inappropriate implementation in cookies in Google Chrome prior to 87.0.4280.66 allowed a remote atta Inappropriate implementation in cookies in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass cookie restrictions via a crafted HTML page.
nvd
CVE-2019-5842P4MEDIUMCVSS 6.5fixed in 75.0.3770.90≥ unspecified, < 75.0.3770.902019-11-25
CVE-2019-5842 [MEDIUM] CWE-416 CVE-2019-5842: Use after free in Blink in Google Chrome prior to 75.0.3770.90 allowed a remote attacker to potentia Use after free in Blink in Google Chrome prior to 75.0.3770.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5862P4MEDIUMCVSS 6.5fixed in 76.0.3809.87≥ unspecified, < 76.0.3809.872019-11-25
CVE-2019-5862 [MEDIUM] CWE-20 CVE-2019-5862: Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote att Insufficient data validation in AppCache in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2019-5865P4MEDIUMCVSS 6.5fixed in 76.0.3809.87≥ unspecified, < 76.0.3809.872019-11-25
CVE-2019-5865 [MEDIUM] CWE-862 CVE-2019-5865: Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remo Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2018-16077P4MEDIUMCVSS 6.5fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-06-27
CVE-2018-16077 [MEDIUM] CWE-285 CVE-2018-16077: Object lifecycle issue in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to Object lifecycle issue in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2011-2863P4MEDIUMCVSS 6.5fixed in 14.0.0.0≥ unspecified, < 14.0.0.02020-06-03
CVE-2011-2863 [MEDIUM] CWE-200 CVE-2011-2863: Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker t Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-13765P4MEDIUMCVSS 6.5fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702020-01-03
CVE-2019-13765 [MEDIUM] CWE-416 CVE-2019-13765: Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote a Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13665P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13665 [MEDIUM] CWE-732 CVE-2019-13665: Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass multiple file download protection via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase