cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 204 of 292
CVE-2019-5834P4MEDIUMCVSS 6.5fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5834 [MEDIUM] CWE-346 CVE-2019-5834: Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attack Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2018-6148P4MEDIUMCVSS 6.5fixed in 67.0.3396.79≥ unspecified, < 67.0.3396.792019-06-27
CVE-2018-6148 [MEDIUM] CWE-93 CVE-2018-6148: Incorrect implementation in Content Security Policy in Google Chrome prior to 67.0.3396.79 allowed a Incorrect implementation in Content Security Policy in Google Chrome prior to 67.0.3396.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6499P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-06-03
CVE-2020-6499 [MEDIUM] CVE-2020-6499: Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote att Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass AppCache security restrictions via a crafted HTML page.
nvd
CVE-2020-6500P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-06-03
CVE-2020-6500 [MEDIUM] CVE-2020-6500: Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remot Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2019-5872P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-5872 [MEDIUM] CWE-416 CVE-2019-5872: Use after free in Mojo in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potential Use after free in Mojo in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2014-3159P4MEDIUMCVSS 6.4≤ 36.0.1985.106v36.0.1985.1+98 more2014-07-20
CVE-2014-3159 [MEDIUM] CWE-20 CVE-2014-3159: The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/ The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/web_contents_delegate_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly restrict URL loading, which allows remote attackers to spoof the URL in the Omnibox via unspecified vectors.
nvd
CVE-2019-13766P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752020-01-03
CVE-2019-13766 [MEDIUM] CWE-416 CVE-2019-13766: Use-after-free in accessibility in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to Use-after-free in accessibility in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6501P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-06-03
CVE-2020-6501 [MEDIUM] CWE-276 CVE-2020-6501: Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attac Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2020-6502P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-06-03
CVE-2020-6502 [MEDIUM] CWE-276 CVE-2020-6502: Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote atta Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2022-0455P4MEDIUMCVSS 6.5fixed in 98.0.4758.80≥ unspecified, < 98.0.4758.802022-04-05
CVE-2022-0455 [MEDIUM] CWE-1021 CVE-2022-0455: Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 a Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2019-13672P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-12-10
CVE-2019-13672 [MEDIUM] CVE-2019-13672: Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page on iOS.
nvd
CVE-2017-5038P4MEDIUMCVSS 6.3≤ 57.0.2987.752017-04-24
CVE-2017-5038 [MEDIUM] CWE-416 CVE-2017-5038: Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.
nvd
CVE-2022-0309P4MEDIUMCVSS 6.5fixed in 97.0.4692.99≥ unspecified, < 97.0.4692.992022-02-12
CVE-2022-0309 [MEDIUM] CWE-863 CVE-2022-0309: Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote att Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2016-5221P4MEDIUMCVSS 6.3≤ 54.0.2840.992017-01-19
CVE-2016-5221 [MEDIUM] CWE-190 CVE-2016-5221: Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Lin Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.
nvd
CVE-2016-1638P4MEDIUMCVSS 6.3≤ 48.0.2564.1162016-03-06
CVE-2016-1638 [MEDIUM] CWE-284 CVE-2016-1638: extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49 extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly restrict use of Web APIs, which allows remote attackers to bypass intended access restrictions via a crafted platform app.
nvd
CVE-2010-3730P4HIGHCVSS 8.8fixed in 6.0.472.622010-10-05
CVE-2010-3730 [HIGH] CVE-2010-3730: Google Chrome before 6.0.472.62 does not properly use information about the origin of a document to Google Chrome before 6.0.472.62 does not properly use information about the origin of a document to manage properties, which allows remote attackers to have an unspecified impact via a crafted web site, related to a "property pollution" issue.
nvd
CVE-2022-3057P4MEDIUMCVSS 6.5fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3057 [MEDIUM] CWE-352 CVE-2022-3057: Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a rem Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-3310P4MEDIUMCVSS 6.5fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3310 [MEDIUM] CWE-602 CVE-2022-3310: Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 al Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chromium security severity: Medium)
nvd
CVE-2022-1497P4MEDIUMCVSS 6.5fixed in 101.0.4951.41≥ unspecified, < 101.0.4951.412022-07-26
CVE-2022-1497 [MEDIUM] CWE-346 CVE-2022-1497: Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attac Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.
nvd
CVE-2019-13664P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13664 [MEDIUM] CWE-346 CVE-2019-13664: Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote att Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase