Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 204 of 292
CVE-2019-5834P4MEDIUMCVSS 6.5fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5834 [MEDIUM] CWE-346 CVE-2019-5834: Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attack
Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2018-6148P4MEDIUMCVSS 6.5fixed in 67.0.3396.79≥ unspecified, < 67.0.3396.792019-06-27
CVE-2018-6148 [MEDIUM] CWE-93 CVE-2018-6148: Incorrect implementation in Content Security Policy in Google Chrome prior to 67.0.3396.79 allowed a
Incorrect implementation in Content Security Policy in Google Chrome prior to 67.0.3396.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6499P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-06-03
CVE-2020-6499 [MEDIUM] CVE-2020-6499: Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote att
Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass AppCache security restrictions via a crafted HTML page.
nvd
CVE-2020-6500P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-06-03
CVE-2020-6500 [MEDIUM] CVE-2020-6500: Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remot
Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2019-5872P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-5872 [MEDIUM] CWE-416 CVE-2019-5872: Use after free in Mojo in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potential
Use after free in Mojo in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2014-3159P4MEDIUMCVSS 6.4≤ 36.0.1985.106v36.0.1985.1+98 more2014-07-20
CVE-2014-3159 [MEDIUM] CWE-20 CVE-2014-3159: The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/
The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/web_contents_delegate_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly restrict URL loading, which allows remote attackers to spoof the URL in the Omnibox via unspecified vectors.
nvd
CVE-2019-13766P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752020-01-03
CVE-2019-13766 [MEDIUM] CWE-416 CVE-2019-13766: Use-after-free in accessibility in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to
Use-after-free in accessibility in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6501P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-06-03
CVE-2020-6501 [MEDIUM] CWE-276 CVE-2020-6501: Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attac
Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2020-6502P4MEDIUMCVSS 6.5fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-06-03
CVE-2020-6502 [MEDIUM] CWE-276 CVE-2020-6502: Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote atta
Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2022-0455P4MEDIUMCVSS 6.5fixed in 98.0.4758.80≥ unspecified, < 98.0.4758.802022-04-05
CVE-2022-0455 [MEDIUM] CWE-1021 CVE-2022-0455: Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 a
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2019-13672P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-12-10
CVE-2019-13672 [MEDIUM] CVE-2019-13672: Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to
Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page on iOS.
nvd
CVE-2017-5038P4MEDIUMCVSS 6.3≤ 57.0.2987.752017-04-24
CVE-2017-5038 [MEDIUM] CWE-416 CVE-2017-5038: Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free
Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.
nvd
CVE-2022-0309P4MEDIUMCVSS 6.5fixed in 97.0.4692.99≥ unspecified, < 97.0.4692.992022-02-12
CVE-2022-0309 [MEDIUM] CWE-863 CVE-2022-0309: Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote att
Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2016-5221P4MEDIUMCVSS 6.3≤ 54.0.2840.992017-01-19
CVE-2016-5221 [MEDIUM] CWE-190 CVE-2016-5221: Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Lin
Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.
nvd
CVE-2016-1638P4MEDIUMCVSS 6.3≤ 48.0.2564.1162016-03-06
CVE-2016-1638 [MEDIUM] CWE-284 CVE-2016-1638: extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49
extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly restrict use of Web APIs, which allows remote attackers to bypass intended access restrictions via a crafted platform app.
nvd
CVE-2010-3730P4HIGHCVSS 8.8fixed in 6.0.472.622010-10-05
CVE-2010-3730 [HIGH] CVE-2010-3730: Google Chrome before 6.0.472.62 does not properly use information about the origin of a document to
Google Chrome before 6.0.472.62 does not properly use information about the origin of a document to manage properties, which allows remote attackers to have an unspecified impact via a crafted web site, related to a "property pollution" issue.
nvd
CVE-2022-3057P4MEDIUMCVSS 6.5fixed in 105.0.5195.52≥ unspecified, < 105.0.5195.522022-09-26
CVE-2022-3057 [MEDIUM] CWE-352 CVE-2022-3057: Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a rem
Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-3310P4MEDIUMCVSS 6.5fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3310 [MEDIUM] CWE-602 CVE-2022-3310: Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 al
Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an application to bypass same origin policy via a crafted application. (Chromium security severity: Medium)
nvd
CVE-2022-1497P4MEDIUMCVSS 6.5fixed in 101.0.4951.41≥ unspecified, < 101.0.4951.412022-07-26
CVE-2022-1497 [MEDIUM] CWE-346 CVE-2022-1497: Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attac
Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to spoof the contents of cross-origin websites via a crafted HTML page.
nvd
CVE-2019-13664P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13664 [MEDIUM] CWE-346 CVE-2019-13664: Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote att
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd