cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 215 of 292
CVE-2026-13933P4MEDIUMCVSS 5.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13933 [MEDIUM] CWE-284 CVE-2026-13933: Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remot Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9124P4MEDIUMCVSS 5.3fixed in 148.0.7778.178≥ 148.0.7778.179, < 148.0.7778.1792026-05-20
CVE-2026-9124 [MEDIUM] CWE-20 CVE-2026-9124: Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allo Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8543P4MEDIUMCVSS 5.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8543 [MEDIUM] CWE-125 CVE-2026-8543: Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote at Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13975P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13975 [MEDIUM] CWE-125 CVE-2026-13975: Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14414P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14414 [MEDIUM] CWE-20 CVE-2026-14414: Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11098P4MEDIUMCVSS 5.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11098 [MEDIUM] CWE-20 CVE-2026-11098: Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-12015P4MEDIUMCVSS 5.3fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12015 [MEDIUM] CWE-416 CVE-2026-12015: Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who ha Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-12025P4MEDIUMCVSS 5.3fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12025 [MEDIUM] CWE-20 CVE-2026-12025: Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allow Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14112P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14112 [MEDIUM] CWE-203 CVE-2026-14112: Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17914P4MEDIUMCVSS 5.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17914 [MEDIUM] CWE-1300 CVE-2026-17914: Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote at Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14049P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14049 [MEDIUM] CWE-200 CVE-2026-14049: Inappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacke Inappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11669P4MEDIUMCVSS 5.3fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11669 [MEDIUM] CWE-472 CVE-2026-11669: Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote at Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17978P4MEDIUMCVSS 5.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17978 [MEDIUM] CWE-1300 CVE-2026-17978: Side-channel information leakage in WebCodecs in Google Chrome prior to 151.0.7922.72 allowed a remo Side-channel information leakage in WebCodecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11246P4MEDIUMCVSS 5.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11246 [MEDIUM] CWE-20 CVE-2026-11246: Insufficient validation of untrusted input in IndexedDB in Google Chrome prior to 149.0.7827.53 allo Insufficient validation of untrusted input in IndexedDB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-12440P4MEDIUMCVSS 5.3fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12440 [MEDIUM] CWE-120 CVE-2025-12440: Inappropriate implementation in Autofill in Google Chrome prior to 142.0.7444.59 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-12909P4MEDIUMCVSS 5.3fixed in 140.0.7339.80≥ 140.0.7339.80, < 140.0.7339.802025-11-08
CVE-2025-12909 [MEDIUM] CWE-693 CVE-2025-12909: Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cross-origin data via Devtools. (Chromium security severity: Low)
nvd
CVE-2026-8535P4MEDIUMCVSS 5.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8535 [MEDIUM] CWE-125 CVE-2026-8535: Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted JPEG file. (Chromium security severity: High)
nvd
CVE-2026-9985P4MEDIUMCVSS 5.3fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9985 [MEDIUM] CWE-20 CVE-2026-9985: Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778 Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14153P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14153 [MEDIUM] CWE-451 CVE-2026-14153: Inappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attack Inappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-3940P4MEDIUMCVSS 5.3fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3940 [MEDIUM] CWE-284 CVE-2026-3940: Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
Google Chrome vulnerabilities | cvebase