cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 213 of 292
CVE-2011-1112P4HIGHCVSS 7.5fixed in 9.0.597.1072011-03-01
CVE-2011-1112 [HIGH] CVE-2011-1112: Google Chrome before 9.0.597.107 does not properly perform SVG rendering, which allows remote attack Google Chrome before 9.0.597.107 does not properly perform SVG rendering, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2010-1229P4CRITICALCVSS 10.0≤ 4.1.249.1035v0.2.149.27+84 more2010-04-01
CVE-2010-1229 [CRITICAL] CWE-399 CVE-2010-1229: The sandbox infrastructure in Google Chrome before 4.1.249.1036 does not properly use pointers, whic The sandbox infrastructure in Google Chrome before 4.1.249.1036 does not properly use pointers, which has unspecified impact and attack vectors.
nvd
CVE-2011-1185P4HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1185 [HIGH] CVE-2011-1185: Google Chrome before 10.0.648.127 does not prevent (1) navigation and (2) close operations on the to Google Chrome before 10.0.648.127 does not prevent (1) navigation and (2) close operations on the top location of a sandboxed frame, which has unspecified impact and remote attack vectors.
nvd
CVE-2012-5122P4HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5122 [HIGH] CWE-399 CVE-2012-5122: Google Chrome before 23.0.1271.64 does not properly perform a cast of an unspecified variable during Google Chrome before 23.0.1271.64 does not properly perform a cast of an unspecified variable during handling of input, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2013-2865P4HIGHCVSS 7.5≤ 27.0.1453.109v27.0.1453.0+79 more2013-06-05
CVE-2013-2865 [HIGH] CVE-2013-2865: Multiple unspecified vulnerabilities in Google Chrome before 27.0.1453.110 allow attackers to cause Multiple unspecified vulnerabilities in Google Chrome before 27.0.1453.110 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2012-2881P4HIGHCVSS 7.5≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2881 [HIGH] CWE-119 CVE-2012-2881: Google Chrome before 22.0.1229.79 does not properly handle plug-ins, which allows remote attackers t Google Chrome before 22.0.1229.79 does not properly handle plug-ins, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2025-5283P4MEDIUMCVSS 5.4fixed in 137.0.7151.55≥ 137.0.7151.55, < 137.0.7151.552025-05-27
CVE-2025-5283 [MEDIUM] CWE-416 CVE-2025-5283: Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potent Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-3900P4HIGHCVSS 7.5fixed in 15.0.874.1212011-11-17
CVE-2011-3900 [HIGH] CWE-787 CVE-2011-3900: Google V8, as used in Google Chrome before 15.0.874.121, allows remote attackers to cause a denial o Google V8, as used in Google Chrome before 15.0.874.121, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write operation.
nvd
CVE-2013-0924P4HIGHCVSS 7.5≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0924 [HIGH] CWE-264 CVE-2013-0924: The extension functionality in Google Chrome before 26.0.1410.43 does not verify that use of the per The extension functionality in Google Chrome before 26.0.1410.43 does not verify that use of the permissions API is consistent with file permissions, which has unspecified impact and attack vectors.
nvd
CVE-2010-3252P4CRITICALCVSS 10.0fixed in 6.0.472.532010-09-07
CVE-2010-3252 [CRITICAL] CWE-416 CVE-2010-3252: Use-after-free vulnerability in the Notifications presenter in Google Chrome before 6.0.472.53 allow Use-after-free vulnerability in the Notifications presenter in Google Chrome before 6.0.472.53 allows attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-2856P4HIGHCVSS 7.5≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2856 [HIGH] CWE-119 CVE-2012-2856: The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.11 The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.
nvd
CVE-2013-2886P4HIGHCVSS 7.5≤ 28.0.1500.94v28.0.1500.0+67 more2013-07-31
CVE-2013-2886 [HIGH] CVE-2013-2886: Multiple unspecified vulnerabilities in Google Chrome before 28.0.1500.95 allow attackers to cause a Multiple unspecified vulnerabilities in Google Chrome before 28.0.1500.95 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2011-1793P4HIGHCVSS 7.5≤ 11.0.696.652014-12-26
CVE-2011-1793 [HIGH] CWE-20 CVE-2011-1793: rendering/svg/RenderSVGResourceFilter.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 a rendering/svg/RenderSVGResourceFilter.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted SVG document that leads to a "stale pointer."
nvd
CVE-2013-2846P4HIGHCVSS 7.5≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2846 [HIGH] CVE-2013-2846: Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2013-2840.
nvd
CVE-2013-2840P4HIGHCVSS 7.5≤ 27.0.1453.91v27.0.1453.0+69 more2013-05-22
CVE-2013-2840 [HIGH] CWE-399 CVE-2013-2840: Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2013-2846.
nvd
CVE-2012-5149P4HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5149 [HIGH] CWE-189 CVE-2012-5149: Integer overflow in the audio IPC layer in Google Chrome before 24.0.1312.52 allows remote attackers Integer overflow in the audio IPC layer in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-2896P4HIGHCVSS 7.5≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2896 [HIGH] CWE-189 CVE-2012-2896: Integer overflow in the WebGL implementation in Google Chrome before 22.0.1229.79 on Mac OS X allows Integer overflow in the WebGL implementation in Google Chrome before 22.0.1229.79 on Mac OS X allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-2863P4HIGHCVSS 7.5≤ 21.0.1180.74v21.0.1180.0+36 more2012-08-09
CVE-2012-2863 [HIGH] CWE-119 CVE-2012-2863: The PDF functionality in Google Chrome before 21.0.1180.75 allows remote attackers to cause a denial The PDF functionality in Google Chrome before 21.0.1180.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.
nvd
CVE-2025-0445P4MEDIUMCVSS 5.4fixed in 133.0.6943.53≥ 133.0.6943.53, < 133.0.6943.532025-02-04
CVE-2025-0445 [MEDIUM] CWE-416 CVE-2025-0445: Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentiall Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2014-1749P4HIGHCVSS 7.5≤ 35.0.1916.113v35.0.1916.0+78 more2014-05-21
CVE-2014-1749 [HIGH] CVE-2014-1749: Multiple unspecified vulnerabilities in Google Chrome before 35.0.1916.114 allow attackers to cause Multiple unspecified vulnerabilities in Google Chrome before 35.0.1916.114 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
Google Chrome vulnerabilities | cvebase