Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 212 of 292
CVE-2026-13836P4MEDIUMCVSS 6.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13836 [MEDIUM] CWE-79 CVE-2026-13836: Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacke
Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14083P4MEDIUMCVSS 6.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14083 [MEDIUM] CWE-20 CVE-2026-14083: Insufficient validation of untrusted input in HTML in Google Chrome prior to 150.0.7871.47 allowed a
Insufficient validation of untrusted input in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14068P4MEDIUMCVSS 6.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14068 [MEDIUM] CWE-79 CVE-2026-14068: Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a rem
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17797P4MEDIUMCVSS 6.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17797 [MEDIUM] CWE-79 CVE-2026-17797: Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacke
Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17845P4MEDIUMCVSS 6.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17845 [MEDIUM] CWE-79 CVE-2026-17845: Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacke
Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17853P4MEDIUMCVSS 6.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17853 [MEDIUM] CWE-79 CVE-2026-17853: Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote at
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17878P4MEDIUMCVSS 6.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17878 [MEDIUM] CWE-79 CVE-2026-17878: Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacke
Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17818P4MEDIUMCVSS 6.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17818 [MEDIUM] CWE-79 CVE-2026-17818: Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote att
Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17827P4MEDIUMCVSS 6.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17827 [MEDIUM] CWE-79 CVE-2026-17827: Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacke
Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5899P4MEDIUMCVSS 6.1fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5899 [MEDIUM] CWE-346 CVE-2026-5899: Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowe
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2020-6394P4MEDIUMCVSS 5.4fixed in 80.0.3987.87≥ unspecified, < 80.0.3987.872020-02-11
CVE-2020-6394 [MEDIUM] CVE-2020-6394: Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote att
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2011-1117P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1117 [HIGH] CVE-2011-1117: Google Chrome before 9.0.597.107 does not properly handle XHTML documents, which allows remote attac
Google Chrome before 9.0.597.107 does not properly handle XHTML documents, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale nodes."
nvd
CVE-2011-1114P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1114 [HIGH] CVE-2011-1114: Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to c
Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
nvd
CVE-2010-1506P4HIGHCVSS 7.8≤ 4.1.249.1058v1.0.154.53+232 more2010-04-23
CVE-2010-1506 [HIGH] CVE-2010-1506: The Google V8 bindings in Google Chrome before 4.1.249.1059 allow attackers to cause a denial of ser
The Google V8 bindings in Google Chrome before 4.1.249.1059 allow attackers to cause a denial of service (memory corruption) via unknown vectors.
nvd
CVE-2011-3103P4HIGHCVSS 7.5≤ 19.0.1084.51v19.0.1028.0+130 more2012-05-24
CVE-2011-3103 [HIGH] CWE-399 CVE-2011-3103: Google V8, as used in Google Chrome before 19.0.1084.52, does not properly perform garbage collectio
Google V8, as used in Google Chrome before 19.0.1084.52, does not properly perform garbage collection, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2010-4038P4HIGHCVSS 7.5fixed in 7.0.517.412010-10-21
CVE-2010-4038 [HIGH] CWE-404 CVE-2010-4038: The Web Sockets implementation in Google Chrome before 7.0.517.41 does not properly handle a shutdow
The Web Sockets implementation in Google Chrome before 7.0.517.41 does not properly handle a shutdown action, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2010-4042P4CRITICALCVSS 9.8fixed in 7.0.517.412010-10-21
CVE-2010-4042 [CRITICAL] CWE-20 CVE-2010-4042: Google Chrome before 7.0.517.41 does not properly handle element maps, which allows remote attackers
Google Chrome before 7.0.517.41 does not properly handle element maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "stale elements."
nvd
CVE-2011-3107P4HIGHCVSS 7.5≤ 19.0.1084.51v19.0.1028.0+130 more2012-05-24
CVE-2011-3107 [HIGH] CVE-2011-3107: Google Chrome before 19.0.1084.52 does not properly implement JavaScript bindings for plug-ins, whic
Google Chrome before 19.0.1084.52 does not properly implement JavaScript bindings for plug-ins, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-1197P4HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1197 [HIGH] CWE-20 CVE-2011-1197: Google Chrome before 10.0.648.127 does not properly perform table painting, which allows remote atta
Google Chrome before 10.0.648.127 does not properly perform table painting, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1189P4HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1189 [HIGH] CVE-2011-1189: Google Chrome before 10.0.648.127 does not properly perform box layout, which allows remote attacker
Google Chrome before 10.0.648.127 does not properly perform box layout, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
nvd