cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 208 of 292
CVE-2011-3880P4HIGHCVSS 7.5fixed in 15.0.874.1022011-10-25
CVE-2011-3880 [HIGH] CWE-20 CVE-2011-3880: Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a deli Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact and remote attack vectors.
nvd
CVE-2010-2903P4HIGHCVSS 7.5fixed in 5.0.375.1252010-07-28
CVE-2010-2903 [HIGH] CVE-2010-2903: Google Chrome before 5.0.375.125 performs unexpected truncation and improper eliding of hostnames, w Google Chrome before 5.0.375.125 performs unexpected truncation and improper eliding of hostnames, which has unspecified impact and remote attack vectors.
nvd
CVE-2013-0907P4HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0907 [HIGH] CWE-362 CVE-2013-0907: Race condition in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of se Race condition in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of media threads.
nvd
CVE-2012-5111P4HIGHCVSS 7.5≤ 22.0.1229.91v22.0.1229.0+54 more2012-10-09
CVE-2012-5111 [HIGH] CVE-2012-5111: Google Chrome before 22.0.1229.92 does not monitor for crashes of Pepper plug-ins, which has unspeci Google Chrome before 22.0.1229.92 does not monitor for crashes of Pepper plug-ins, which has unspecified impact and remote attack vectors.
nvd
CVE-2026-13911P4MEDIUMCVSS 5.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13911 [MEDIUM] CWE-20 CVE-2026-13911: Insufficient policy enforcement in Spellcheck in Google Chrome prior to 150.0.7871.47 allowed a remo Insufficient policy enforcement in Spellcheck in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2013-0925P4HIGHCVSS 7.5≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0925 [HIGH] CWE-264 CVE-2013-0925: Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission: Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission::kTab) permission before providing a URL to this extension, which has unspecified impact and remote attack vectors.
nvd
CVE-2026-13875P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13875 [MEDIUM] CWE-20 CVE-2026-13875: Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 150.0.7871.47 Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-15771P4MEDIUMCVSS 5.3fixed in 150.0.7871.125≥ 150.0.7871.125, < 150.0.7871.1252026-07-14
CVE-2026-15771 [MEDIUM] CWE-20 CVE-2026-15771: Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871. Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13961P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13961 [MEDIUM] CWE-20 CVE-2026-13961: Insufficient validation of untrusted input in DevTools in Google Chrome on Windows prior to 150.0.78 Insufficient validation of untrusted input in DevTools in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11005P4MEDIUMCVSS 5.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11005 [MEDIUM] CWE-125 CVE-2026-11005: Out of bounds read in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote atta Out of bounds read in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11004P4MEDIUMCVSS 5.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11004 [MEDIUM] CWE-125 CVE-2026-11004: Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who ha Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13890P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13890 [MEDIUM] CWE-125 CVE-2026-13890: Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker w Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2013-0886P4HIGHCVSS 7.5≤ 25.0.1364.98v25.0.1364.0+86 more2013-02-23
CVE-2013-0886 [HIGH] CVE-2013-0886: Google Chrome before 25.0.1364.99 on Mac OS X does not properly implement signal handling for Native Google Chrome before 25.0.1364.99 on Mac OS X does not properly implement signal handling for Native Client (aka NaCl) code, which has unspecified impact and attack vectors.
nvd
CVE-2026-14117P4MEDIUMCVSS 5.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14117 [MEDIUM] CWE-20 CVE-2026-14117: Insufficient validation of untrusted input in DevTools in Google Chrome on Windows prior to 150.0.78 Insufficient validation of untrusted input in DevTools in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-8516P4MEDIUMCVSS 5.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8516 [MEDIUM] CWE-20 CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-3939P4MEDIUMCVSS 5.3fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3939 [MEDIUM] CWE-284 CVE-2026-3939: Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote atta Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file. (Chromium security severity: Low)
nvd
CVE-2012-2871P4MEDIUMCVSS 6.8≤ 21.0.1180.88v21.0.1180.0+50 more2012-08-31
CVE-2012-2871 [MEDIUM] CVE-2012-2871: libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly suppo libxml2 2.9.0-rc1 and earlier, as used in Google Chrome before 21.0.1180.89, does not properly support a cast of an unspecified variable during handling of XSL transforms, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document, related to the _xmlNs data structure in include/libxml/tree.h.
nvd
CVE-2012-1521P4MEDIUMCVSS 6.8fixed in 18.0.1025.1682012-05-01
CVE-2012-1521 [MEDIUM] CWE-416 CVE-2012-1521: Use-after-free vulnerability in the XML parser in Google Chrome before 18.0.1025.168 allows remote a Use-after-free vulnerability in the XML parser in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3078P4MEDIUMCVSS 6.8fixed in 18.0.1025.1682012-05-01
CVE-2011-3078 [MEDIUM] CWE-416 CVE-2011-3078: Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.168 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the floating of elements, a different vulnerability than CVE-2011-3081.
nvd
CVE-2011-3075P4MEDIUMCVSS 6.8fixed in 18.0.1025.1512012-04-05
CVE-2011-3075 [MEDIUM] CWE-416 CVE-2011-3075: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to style-application commands.
nvd
Google Chrome vulnerabilities | cvebase