cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82

Vulnerabilities

Page 21 of 292
CVE-2026-14407P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14407 [HIGH] CWE-94 CVE-2026-14407: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10013P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-10013 [HIGH] CWE-416 CVE-2026-10013: Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to ex Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9938P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9938 [HIGH] CWE-94 CVE-2026-9938: Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacke Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11650P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11650 [HIGH] CWE-416 CVE-2026-11650: Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute a Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11649P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11649 [HIGH] CWE-416 CVE-2026-11649: Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute a Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11076P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11076 [HIGH] CWE-843 CVE-2026-11076: Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute a Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9878P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9878 [HIGH] CWE-416 CVE-2026-9878: Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-7898P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7898 [HIGH] CWE-416 CVE-2026-7898: Use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attac Use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
nvd
CVE-2026-7363P3HIGHCVSS 8.8fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7363 [HIGH] CWE-416 CVE-2026-7363: Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remot Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-15121P3HIGHCVSS 8.8fixed in 150.0.7871.115≥ 150.0.7871.115, < 150.0.7871.1152026-07-08
CVE-2026-15121 [HIGH] CWE-416 CVE-2026-15121: Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execu Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11683P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11683 [HIGH] CWE-416 CVE-2026-11683: Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to ex Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8016P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8016 [HIGH] CWE-416 CVE-2026-8016: Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execut Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-7988P3HIGHCVSS 8.8fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7988 [HIGH] CWE-843 CVE-2026-7988: Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execut Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8540P3HIGHCVSS 8.8fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8540 [HIGH] CWE-843 CVE-2026-8540: Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute a Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9927P3HIGHCVSS 8.8fixed in 148.0.7778.215fixed in 148.0.7778.216+1 more2026-05-28
CVE-2026-9927 [HIGH] CWE-416 CVE-2026-9927: Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9941P3HIGHCVSS 8.8fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9941 [HIGH] CWE-416 CVE-2026-9941: Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execut Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9947P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9947 [HIGH] CWE-416 CVE-2026-9947: Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9945P3HIGHCVSS 8.8fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9945 [HIGH] CWE-416 CVE-2026-9945: Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacke Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5862P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5862 [HIGH] CVE-2026-5862: Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5877P3HIGHCVSS 8.8fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5877 [HIGH] CWE-416 CVE-2026-5877: Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to ex Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase