Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 207 of 292
CVE-2012-5141P4CRITICALCVSS 10.0≤ 23.0.1271.96v23.0.1271.0+66 more2012-12-12
CVE-2012-5141 [CRITICAL] CVE-2012-5141: Google Chrome before 23.0.1271.97 does not properly restrict instantiation of the Chromoting client
Google Chrome before 23.0.1271.97 does not properly restrict instantiation of the Chromoting client plug-in, which has unspecified impact and attack vectors.
nvd
CVE-2011-3891P4HIGHCVSS 7.5fixed in 15.0.874.1022011-10-25
CVE-2011-3891 [HIGH] CVE-2011-3891: Google Chrome before 15.0.874.102 does not properly restrict access to internal Google V8 functions,
Google Chrome before 15.0.874.102 does not properly restrict access to internal Google V8 functions, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-0842P4CRITICALCVSS 10.0≤ 24.0.1312.55v24.0.1272.0+114 more2013-01-24
CVE-2013-0842 [CRITICAL] CVE-2013-0842: Google Chrome before 24.0.1312.56 does not properly handle %00 characters in pathnames, which has un
Google Chrome before 24.0.1312.56 does not properly handle %00 characters in pathnames, which has unspecified impact and attack vectors.
nvd
CVE-2012-2830P4HIGHCVSS 7.5≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2830 [HIGH] CVE-2012-2830: Google Chrome before 20.0.1132.43 does not properly set array values, which allows remote attackers
Google Chrome before 20.0.1132.43 does not properly set array values, which allows remote attackers to cause a denial of service (incorrect pointer use) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2013-0896P4HIGHCVSS 7.5fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0896 [HIGH] CWE-119 CVE-2013-0896: Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does no
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly manage memory during message handling for plug-ins, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3914P4HIGHCVSS 7.5fixed in 16.0.912.632011-12-13
CVE-2011-3914 [HIGH] CWE-787 CVE-2011-3914: The internationalization (aka i18n) functionality in Google V8, as used in Google Chrome before 16.0
The internationalization (aka i18n) functionality in Google V8, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.
nvd
CVE-2010-3253P4CRITICALCVSS 10.0fixed in 6.0.472.532010-09-07
CVE-2010-3253 [CRITICAL] CWE-119 CVE-2010-3253: The implementation of notification permissions in Google Chrome before 6.0.472.53 allows attackers t
The implementation of notification permissions in Google Chrome before 6.0.472.53 allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3883P4HIGHCVSS 7.5fixed in 15.0.874.1022011-10-25
CVE-2011-3883 [HIGH] CWE-416 CVE-2011-3883: Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to counters.
nvd
CVE-2011-3890P4HIGHCVSS 7.5fixed in 15.0.874.1022011-10-25
CVE-2011-3890 [HIGH] CWE-416 CVE-2011-3890: Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to video source handling.
nvd
CVE-2013-2854P4HIGHCVSS 7.5≤ 27.0.1453.109v27.0.1453.0+79 more2013-06-05
CVE-2013-2854 [HIGH] CVE-2013-2854: Google Chrome before 27.0.1453.110 on Windows provides an incorrect handle to a renderer process in
Google Chrome before 27.0.1453.110 on Windows provides an incorrect handle to a renderer process in unspecified circumstances, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2013-2862P4HIGHCVSS 7.5≤ 27.0.1453.109v27.0.1453.0+79 more2013-06-05
CVE-2013-2862 [HIGH] CWE-119 CVE-2013-2862: Skia, as used in Google Chrome before 27.0.1453.110, does not properly handle GPU acceleration, whic
Skia, as used in Google Chrome before 27.0.1453.110, does not properly handle GPU acceleration, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-1798P4HIGHCVSS 7.5≤ 11.0.696.642014-12-26
CVE-2011-1798 [HIGH] CWE-20 CVE-2011-1798: rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not pr
rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not properly perform a cast of an unspecified variable during an attempt to handle a block child, which allows remote attackers to cause a denial of service (application crash) or possibly have unknown other impact via a crafted text element in an SVG document.
nvd
CVE-2011-1796P4HIGHCVSS 7.5≤ 11.0.696.642014-12-26
CVE-2011-1796 [HIGH] CVE-2011-1796: Use-after-free vulnerability in the FrameView::calculateScrollbarModesForLayout function in page/Fra
Use-after-free vulnerability in the FrameView::calculateScrollbarModesForLayout function in page/FrameView.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that calls the removeChild method during interaction
nvd
CVE-2013-2839P4HIGHCVSS 7.5≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2839 [HIGH] CWE-399 CVE-2013-2839: Google Chrome before 27.0.1453.93 does not properly perform a cast of an unspecified variable during
Google Chrome before 27.0.1453.93 does not properly perform a cast of an unspecified variable during handling of clipboard data, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2013-0837P4HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0837 [HIGH] CWE-20 CVE-2013-0837: Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly h
Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of extension tabs.
nvd
CVE-2013-0904P4HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0904 [HIGH] CWE-119 CVE-2013-0904: The Web Audio implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause
The Web Audio implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3882P4HIGHCVSS 7.5fixed in 15.0.874.1022011-10-25
CVE-2011-3882 [HIGH] CWE-416 CVE-2011-3882: Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media buffers.
nvd
CVE-2011-2842P4HIGHCVSS 7.5fixed in 14.0.835.1632011-09-19
CVE-2011-2842 [HIGH] CWE-20 CVE-2011-2842: The installer in Google Chrome before 14.0.835.163 on Mac OS X does not properly handle lock files,
The installer in Google Chrome before 14.0.835.163 on Mac OS X does not properly handle lock files, which has unspecified impact and attack vectors.
nvd
CVE-2026-0903P4MEDIUMCVSS 5.4fixed in 144.0.7559.59fixed in 144.0.7559.60+1 more2026-01-20
CVE-2026-0903 [MEDIUM] CWE-20 CVE-2026-0903: Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type protections via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2026-17761P4MEDIUMCVSS 5.4fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17761 [MEDIUM] CWE-20 CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)
nvd