Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 214 of 292
CVE-2011-2838P4HIGHCVSS 7.5fixed in 14.0.835.1632011-09-19
CVE-2011-2838 [HIGH] CWE-20 CVE-2011-2838: Google Chrome before 14.0.835.163 does not properly consider the MIME type during the loading of a p
Google Chrome before 14.0.835.163 does not properly consider the MIME type during the loading of a plug-in, which has unspecified impact and remote attack vectors.
nvd
CVE-2011-1303P4HIGHCVSS 7.5fixed in 11.0.696.572011-05-03
CVE-2011-1303 [HIGH] CWE-20 CVE-2011-1303: Google Chrome before 11.0.696.57 does not properly handle floating objects, which allows remote atta
Google Chrome before 11.0.696.57 does not properly handle floating objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-2829P4HIGHCVSS 7.5fixed in 13.0.782.2152011-08-29
CVE-2011-2829 [HIGH] CWE-190 CVE-2011-2829: Integer overflow in Google Chrome before 13.0.782.215 on 32-bit platforms allows remote attackers to
Integer overflow in Google Chrome before 13.0.782.215 on 32-bit platforms allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving uniform arrays.
nvd
CVE-2015-1226P4MEDIUMCVSS 5.0≤ 40.0.2214.1152015-03-09
CVE-2015-1226 [MEDIUM] CWE-264 CVE-2015-1226: The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in G
The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properly restrict what URLs are available as debugger targets, which allows remote attackers to bypass intended access restrictions via a crafted extension.
nvd
CVE-2015-1270P4MEDIUMCVSS 6.8≤ 43.0.2357.1342015-07-23
CVE-2015-1270 [MEDIUM] CWE-19 CVE-2015-1270: The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode
The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted f
nvd
CVE-2026-17915P4MEDIUMCVSS 5.4fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17915 [MEDIUM] CWE-451 CVE-2026-17915: Inappropriate implementation in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a
Inappropriate implementation in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-6557P4MEDIUMCVSS 5.4fixed in 138.0.7204.49≥ 138.0.7204.49, < 138.0.7204.492025-06-24
CVE-2025-6557 [MEDIUM] CWE-1021 CVE-2025-6557: Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed
Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14131P4MEDIUMCVSS 5.4fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14131 [MEDIUM] CWE-20 CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14135P4MEDIUMCVSS 5.4fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14135 [MEDIUM] CWE-20 CVE-2026-14135: Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowe
Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14150P4MEDIUMCVSS 5.4fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14150 [MEDIUM] CWE-20 CVE-2026-14150: Insufficient validation of untrusted input in Speech in Google Chrome prior to 150.0.7871.47 allowed
Insufficient validation of untrusted input in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11157P4MEDIUMCVSS 5.4fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11157 [MEDIUM] CWE-94 CVE-2026-11157: Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who co
Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2012-2821P4HIGHCVSS 7.5≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2821 [HIGH] CVE-2012-2821: The autofill implementation in Google Chrome before 20.0.1132.43 does not properly display text, whi
The autofill implementation in Google Chrome before 20.0.1132.43 does not properly display text, which has unspecified impact and remote attack vectors.
nvd
CVE-2012-5148P4HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5148 [HIGH] CWE-20 CVE-2012-5148: The hyphenation functionality in Google Chrome before 24.0.1312.52 does not properly validate file n
The hyphenation functionality in Google Chrome before 24.0.1312.52 does not properly validate file names, which has unspecified impact and attack vectors.
nvd
CVE-2026-13950P4MEDIUMCVSS 5.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13950 [MEDIUM] CWE-457 CVE-2026-13950: Uninitialized Use in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had c
Uninitialized Use in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13947P4MEDIUMCVSS 5.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13947 [MEDIUM] CWE-457 CVE-2026-13947: Uninitialized Use in XR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had co
Uninitialized Use in XR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2013-0830P4HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2013-0830 [HIGH] CWE-20 CVE-2013-0830: The IPC layer in Google Chrome before 24.0.1312.52 on Windows omits a NUL character required for ter
The IPC layer in Google Chrome before 24.0.1312.52 on Windows omits a NUL character required for termination of an unspecified data structure, which has unknown impact and attack vectors.
nvd
CVE-2026-13969P4MEDIUMCVSS 5.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13969 [MEDIUM] CWE-457 CVE-2026-13969: Uninitialized Use in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker
Uninitialized Use in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13971P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13971 [MEDIUM] CWE-457 CVE-2026-13971: Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13970P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13970 [MEDIUM] CWE-457 CVE-2026-13970: Uninitialized Use in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had
Uninitialized Use in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13877P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13877 [MEDIUM] CWE-20 CVE-2026-13877: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd