cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 211 of 292
CVE-2018-6119P4MEDIUMCVSS 6.5fixed in 64.0.3282.119≥ unspecified, < 64.0.3282.1192018-09-25
CVE-2018-6119 [MEDIUM] CWE-20 CVE-2018-6119: Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker t Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-16069P4MEDIUMCVSS 6.5fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-06-27
CVE-2018-16069 [MEDIUM] CWE-125 CVE-2018-16069: Unintended floating-point error accumulation in SwiftShader in Google Chrome prior to 69.0.3497.81 a Unintended floating-point error accumulation in SwiftShader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5802P4MEDIUMCVSS 6.5fixed in 73.0.3683.75vprior to 73.0.3683.752019-05-23
CVE-2019-5802 [MEDIUM] CVE-2019-5802: Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2018-6159P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-6159 [MEDIUM] CWE-200 CVE-2018-6159: Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 68.0.3440.75 allowed a re Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2018-6168P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-6168 [MEDIUM] CWE-200 CVE-2018-6168: Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to Information leak in media engine in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2020-6503P4MEDIUMCVSS 6.5fixed in 74.0.3729.108≥ unspecified, < 74.0.3729.1082020-06-03
CVE-2020-6503 [MEDIUM] CWE-209 CVE-2020-6503: Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remo Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-13678P4MEDIUMCVSS 6.5fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13678 [MEDIUM] CVE-2019-13678: Incorrect data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attac Incorrect data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2017-5066P4MEDIUMCVSS 6.5fixed in 58.0.3029.81fixed in 58.0.3029.832017-10-27
CVE-2017-5066 [MEDIUM] CWE-347 CVE-2017-5066: Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to incorrectly accept a badly formed X.509 certificate via a crafted HTML page.
nvd
CVE-2019-5857P4MEDIUMCVSS 6.5fixed in 76.0.3809.87≥ unspecified, < 76.0.3809.872019-11-25
CVE-2019-5857 [MEDIUM] CWE-787 CVE-2019-5857: Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote a Inappropriate implementation in JavaScript in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
nvd
CVE-2018-6155P4MEDIUMCVSS 6.5fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-06-27
CVE-2018-6155 [MEDIUM] CWE-416 CVE-2018-6155: Incorrect handling of frames in the VP8 parser in Google Chrome prior to 68.0.3440.75 allowed a remo Incorrect handling of frames in the VP8 parser in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
nvd
CVE-2017-5019P4MEDIUMCVSS 6.3≤ 55.0.2883.872017-02-17
CVE-2017-5019 [MEDIUM] CWE-416 CVE-2017-5019: A use after free in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 A use after free in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2013-6659P4MEDIUMCVSS 6.4≤ 33.0.1750.116v33.0.1750.0+95 more2014-02-24
CVE-2013-6659 [MEDIUM] CWE-310 CVE-2013-6659: The SSLClientSocketNSS::Core::OwnAuthCertHandler function in net/socket/ssl_client_socket_nss.cc in The SSLClientSocketNSS::Core::OwnAuthCertHandler function in net/socket/ssl_client_socket_nss.cc in Google Chrome before 33.0.1750.117 does not prevent changes to server X.509 certificates during renegotiations, which allows remote SSL servers to trigger use of a new certificate chain, inconsistent with the user's expectations, by initiating a TLS rene
nvd
CVE-2019-5754P4MEDIUMCVSS 6.5fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5754 [MEDIUM] CWE-327 CVE-2019-5754: Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker r Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy.
nvd
CVE-2019-5848P4MEDIUMCVSS 6.5fixed in 75.0.3770.142≥ unspecified, < 75.0.3770.1422019-11-25
CVE-2019-5848 [MEDIUM] CWE-312 CVE-2019-5848: Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacke Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2018-20070P4MEDIUMCVSS 6.5fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802019-01-09
CVE-2018-20070 [MEDIUM] CWE-20 CVE-2018-20070: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2017-5090P4MEDIUMCVSS 6.5fixed in 59.0.3071.1152017-10-27
CVE-2017-5090 [MEDIUM] CWE-20 CVE-2017-5090: Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.115 for Mac allowed a Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.115 for Mac allowed a remote attacker to perform domain spoofing via a crafted domain name containing a U+0620 character, aka Apple rdar problem 32458012.
nvd
CVE-2024-3847P4MEDIUMCVSS 6.1fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-04-17
CVE-2024-3847 [MEDIUM] CWE-79 CVE-2024-3847: Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote at Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2013-6802P4MEDIUMCVSS 5.8≤ 31.0.1650.572013-11-18
CVE-2013-6802 [MEDIUM] CVE-2013-6802: Google Chrome before 31.0.1650.57 allows remote attackers to bypass intended sandbox restrictions by Google Chrome before 31.0.1650.57 allows remote attackers to bypass intended sandbox restrictions by leveraging access to a renderer process, as demonstrated during a Mobile Pwn2Own competition at PacSec 2013, a different vulnerability than CVE-2013-6632.
nvd
CVE-2026-17966P4MEDIUMCVSS 6.2fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17966 [MEDIUM] CWE-200 CVE-2026-17966: Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17996P4MEDIUMCVSS 6.2fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17996 [MEDIUM] CWE-284 CVE-2026-17996: Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a loc Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)
nvd
Google Chrome vulnerabilities | cvebase