cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 210 of 292
CVE-2026-17735P4UNKNOWN≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17735 CWE-20 CVE-2026-17735: Insufficient validation of untrusted input in BFCache in Google Chrome prior to 151.0.7922.72 allowe Insufficient validation of untrusted input in BFCache in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2018-6108P4MEDIUMCVSS 6.5fixed in 66.0.3359.117≥ unspecified, < 66.0.3359.1172018-12-04
CVE-2018-6108 [MEDIUM] CVE-2018-6108: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted HTML page.
nvd
CVE-2017-5093P4MEDIUMCVSS 6.5fixed in 60.0.3112.782017-10-27
CVE-2017-5093 [MEDIUM] CWE-20 CVE-2017-5093: Inappropriate implementation in modal dialog handling in Blink in Google Chrome prior to 60.0.3112.7 Inappropriate implementation in modal dialog handling in Blink in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to prevent a full screen warning from being displayed via a crafted HTML page.
nvd
CVE-2017-5104P4MEDIUMCVSS 6.5≤ 60.0.3112.782017-10-27
CVE-2017-5104 [MEDIUM] CWE-20 CVE-2017-5104: Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to spoof the contents of the omnibox via a crafted HTML page.
nvd
CVE-2011-3956P4MEDIUMCVSS 6.8fixed in 17.0.963.462012-02-09
CVE-2011-3956 [MEDIUM] CWE-346 CVE-2011-3956: The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed The extension implementation in Google Chrome before 17.0.963.46 does not properly handle sandboxed origins, which might allow remote attackers to bypass the Same Origin Policy via a crafted extension.
nvd
CVE-2017-5101P4MEDIUMCVSS 6.5≤ 60.0.3112.782017-10-27
CVE-2017-5101 [MEDIUM] CVE-2017-5101: Inappropriate implementation in Omnibox in Google Chrome prior to 60.0.3112.78 for Linux, Windows, a Inappropriate implementation in Omnibox in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.
nvd
CVE-2017-5013P4MEDIUMCVSS 6.5≤ 55.0.2883.872017-02-17
CVE-2017-5013 [MEDIUM] CVE-2017-5013: Google Chrome prior to 56.0.2924.76 for Linux incorrectly handled new tab page navigations in non-se Google Chrome prior to 56.0.2924.76 for Linux incorrectly handled new tab page navigations in non-selected tabs, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2017-15395P4MEDIUMCVSS 6.5fixed in 62.0.3202.622018-02-07
CVE-2017-15395 [MEDIUM] CWE-416 CVE-2017-15395: A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potent A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka an ImageCapture NULL pointer dereference.
nvd
CVE-2016-5187P4MEDIUMCVSS 6.5≤ 53.0.2785.1432016-12-18
CVE-2016-5187 [MEDIUM] CWE-20 CVE-2016-5187: Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of full screen mode, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via crafted HTML pages.
nvd
CVE-2017-5072P4MEDIUMCVSS 6.5fixed in 59.0.3071.922017-10-27
CVE-2017-5072 [MEDIUM] CWE-20 CVE-2017-5072: Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with RTL characters via a crafted URL page.
nvd
CVE-2016-5192P4MEDIUMCVSS 6.5≤ 53.0.2785.1432016-12-18
CVE-2016-5192 [MEDIUM] CWE-284 CVE-2016-5192: Blink in Google Chrome prior to 54.0.2840.59 for Windows missed a CORS check on redirect in TextTrac Blink in Google Chrome prior to 54.0.2840.59 for Windows missed a CORS check on redirect in TextTrackLoader, which allowed a remote attacker to bypass cross-origin restrictions via crafted HTML pages.
nvd
CVE-2016-5155P4MEDIUMCVSS 6.5≤ 52.0.2743.1162016-09-11
CVE-2016-5155 [MEDIUM] CWE-254 CVE-2016-5155: Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not prop Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly validate access to the initial document, which allows remote attackers to spoof the address bar via a crafted web site.
nvd
CVE-2019-5794P4MEDIUMCVSS 6.5fixed in 73.0.3683.75vprior to 73.0.3683.752019-05-23
CVE-2019-5794 [MEDIUM] CVE-2019-5794: Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowe Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2016-5222P4MEDIUMCVSS 6.5≤ 54.0.2840.992017-01-19
CVE-2016-5222 [MEDIUM] CWE-20 CVE-2016-5222: Incorrect handling of invalid URLs in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux Incorrect handling of invalid URLs in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2019-5810P4MEDIUMCVSS 6.5fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082019-06-27
CVE-2019-5810 [MEDIUM] CWE-312 CVE-2019-5810: Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to ob Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-5852P4MEDIUMCVSS 6.5fixed in 76.0.3809.87≥ unspecified, < 76.0.3809.872019-11-25
CVE-2019-5852 [MEDIUM] CWE-20 CVE-2019-5852: Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote a Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-13748P4MEDIUMCVSS 6.5fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13748 [MEDIUM] CWE-862 CVE-2019-13748: Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-5801P4MEDIUMCVSS 6.5fixed in 73.0.3683.75vprior to 73.0.3683.752019-05-23
CVE-2019-5801 [MEDIUM] CWE-20 CVE-2019-5801: Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2018-17459P4MEDIUMCVSS 6.5fixed in 69.0.3497.92≥ unspecified, < 69.0.3497.922019-01-09
CVE-2018-17459 [MEDIUM] CVE-2018-17459: Incorrect handling of clicks in the omnibox in Navigation in Google Chrome prior to 69.0.3497.92 all Incorrect handling of clicks in the omnibox in Navigation in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-6160P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6160 [MEDIUM] CWE-20 CVE-2018-6160: JavaScript alert handling in Prompts in Google Chrome prior to 68.0.3440.75 allowed a remote attacke JavaScript alert handling in Prompts in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
Google Chrome vulnerabilities | cvebase