cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 205 of 292
CVE-2016-5215P4MEDIUMCVSS 6.3≤ 54.0.2840.992017-01-19
CVE-2016-5215 [MEDIUM] CWE-416 CVE-2016-5215: A use after free in webaudio in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and A use after free in webaudio in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2016-5219P4MEDIUMCVSS 6.3≤ 54.0.2840.992017-01-19
CVE-2016-5219 [MEDIUM] CWE-416 CVE-2016-5219: A heap use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 5 A heap use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-5892P4MEDIUMCVSS 6.6fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5892 [MEDIUM] CWE-1268 CVE-2026-5892: Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 allowed a remote att Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to install a PWA without user consent via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2016-5190P4MEDIUMCVSS 6.3≤ 53.0.2785.1432016-12-18
CVE-2016-5190 [MEDIUM] CWE-416 CVE-2016-5190: Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectl Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles during shutdown, which allowed a remote attacker to perform an out of bounds memory read via crafted HTML pages.
nvd
CVE-2016-5216P4MEDIUMCVSS 6.3≤ 54.0.2840.992017-01-19
CVE-2016-5216 [MEDIUM] CWE-416 CVE-2016-5216: A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55 A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
nvd
CVE-2026-14048P4MEDIUMCVSS 6.5fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14048 [MEDIUM] CWE-416 CVE-2026-14048: Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the loca Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (Chromium security severity: Low)
nvd
CVE-2020-16046P4MEDIUMCVSS 6.1fixed in 84.0.4147.105≥ unspecified, < 84.0.4147.1052021-01-14
CVE-2020-16046 [MEDIUM] CWE-79 CVE-2020-16046: Script injection in iOSWeb in Google Chrome on iOS prior to 84.0.4147.105 allowed a remote attacker Script injection in iOSWeb in Google Chrome on iOS prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2026-10916P4MEDIUMCVSS 6.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10916 [MEDIUM] CWE-20 CVE-2026-10916: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allow Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11034P4MEDIUMCVSS 6.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11034 [MEDIUM] CWE-20 CVE-2026-11034: Insufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 14 Insufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)
nvd
CVE-2026-7953P4MEDIUMCVSS 6.1fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7953 [MEDIUM] CWE-20 CVE-2026-7953: Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 148.0.7778.96 allowe Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-11273P4MEDIUMCVSS 6.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11273 [MEDIUM] CWE-20 CVE-2026-11273: Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowe Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11205P4MEDIUMCVSS 6.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11205 [MEDIUM] CWE-20 CVE-2026-11205: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 149.0. Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted QR code. (Chromium security severity: Medium)
nvd
CVE-2026-11229P4MEDIUMCVSS 6.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11229 [MEDIUM] CWE-269 CVE-2026-11229: Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local a Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security severity: Low)
nvd
CVE-2011-1111P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1111 [HIGH] CWE-20 CVE-2011-1111: Google Chrome before 9.0.597.107 does not properly implement forms controls, which allows remote att Google Chrome before 9.0.597.107 does not properly implement forms controls, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-1296P4HIGHCVSS 7.5fixed in 10.0.648.2042011-03-25
CVE-2011-1296 [HIGH] CWE-20 CVE-2011-1296: Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers t Google Chrome before 10.0.648.204 does not properly handle SVG text, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1115P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1115 [HIGH] CVE-2011-1115: Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to c Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2026-13976P4MEDIUMCVSS 5.8fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13976 [MEDIUM] CWE-122 CVE-2026-13976: Insufficient data validation in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote att Insufficient data validation in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-1451P4HIGHCVSS 7.5fixed in 11.0.696.572011-05-03
CVE-2011-1451 [HIGH] CWE-20 CVE-2011-1451: Google Chrome before 11.0.696.57 does not properly handle DOM id maps, which allows remote attackers Google Chrome before 11.0.696.57 does not properly handle DOM id maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "dangling pointers."
nvd
CVE-2011-1295P4HIGHCVSS 7.5fixed in 10.0.648.2042011-03-25
CVE-2011-1295 [HIGH] CWE-20 CVE-2011-1295: WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properl WebKit, as used in Google Chrome before 10.0.648.204 and Apple Safari before 5.0.6, does not properly handle node parentage, which allows remote attackers to cause a denial of service (DOM tree corruption), conduct cross-site scripting (XSS) attacks, or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2010-3117P4CRITICALCVSS 10.0fixed in 5.0.375.1272010-08-24
CVE-2010-3117 [CRITICAL] CVE-2010-3117: Google Chrome before 5.0.375.127 does not properly implement the notifications feature, which allows Google Chrome before 5.0.375.127 does not properly implement the notifications feature, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via unknown vectors.
nvd
Google Chrome vulnerabilities | cvebase