Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 216 of 292
CVE-2026-3930P4MEDIUMCVSS 5.3fixed in 146.0.7680.71≥ 146.0.7680.71, < 146.0.7680.712026-03-11
CVE-2026-3930 [MEDIUM] CWE-288 CVE-2026-3930: Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote atta
Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2012-2827P4HIGHCVSS 7.5≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2827 [HIGH] CWE-399 CVE-2012-2827: Use-after-free vulnerability in the UI in Google Chrome before 20.0.1132.43 on Mac OS X allows attac
Use-after-free vulnerability in the UI in Google Chrome before 20.0.1132.43 on Mac OS X allows attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3031P4MEDIUMCVSS 6.8fixed in 17.0.963.652012-03-05
CVE-2011-3031 [MEDIUM] CWE-416 CVE-2011-3031: Use-after-free vulnerability in the element wrapper in Google V8, as used in Google Chrome before 17
Use-after-free vulnerability in the element wrapper in Google V8, as used in Google Chrome before 17.0.963.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2009-3456P4HIGHCVSS 7.5≤ 3.0.195.21v0.2.149.27+41 more2009-09-29
CVE-2009-3456 [HIGH] CVE-2009-3456: Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\0' character in a domai
Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. NOTE: the p
nvd
CVE-2011-3640P4HIGHCVSS 7.1fixed in 17.02011-10-28
CVE-2011-3640 [HIGH] CWE-426 CVE-2011-3640: Untrusted search path vulnerability in Mozilla Network Security Services (NSS), as used in Google Ch
Untrusted search path vulnerability in Mozilla Network Security Services (NSS), as used in Google Chrome before 17 on Windows and Mac OS X, might allow local users to gain privileges via a Trojan horse pkcs11.txt file in a top-level directory. NOTE: the vendor's response was "Strange behavior, but we're not treating this as a security bug."
nvd
CVE-2011-3050P4MEDIUMCVSS 6.8fixed in 17.0.963.832012-03-22
CVE-2011-3050 [MEDIUM] CWE-416 CVE-2011-3050: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome bef
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter pseudo-element.
nvd
CVE-2011-3077P4MEDIUMCVSS 6.8fixed in 18.0.1025.1512012-04-05
CVE-2011-3077 [MEDIUM] CWE-416 CVE-2011-3077: Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause
Use-after-free vulnerability in Google Chrome before 18.0.1025.151 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the script bindings, related to a "read-after-free" issue.
nvd
CVE-2011-3032P4MEDIUMCVSS 6.8fixed in 17.0.963.652012-03-05
CVE-2011-3032 [MEDIUM] CWE-416 CVE-2011-3032: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of SVG values.
nvd
CVE-2011-3051P4MEDIUMCVSS 6.8fixed in 17.0.963.832012-03-22
CVE-2011-3051 [MEDIUM] CWE-416 CVE-2011-3051: Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome bef
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the cross-fade function.
nvd
CVE-2011-3041P4MEDIUMCVSS 6.8fixed in 17.0.963.652012-03-05
CVE-2011-3041 [MEDIUM] CWE-416 CVE-2011-3041: Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of class attributes.
nvd
CVE-2026-17737P4MEDIUMCVSS 5.0fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17737 [MEDIUM] CWE-416 CVE-2026-17737: Use after free in Bluetooth in Google Chrome on Android prior to 151.0.7922.72 allowed a remote atta
Use after free in Bluetooth in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-1449P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1449 [MEDIUM] CWE-416 CVE-2011-1449: Use-after-free vulnerability in the WebSockets implementation in Google Chrome before 11.0.696.57 al
Use-after-free vulnerability in the WebSockets implementation in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-2790P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2790 [MEDIUM] CWE-416 CVE-2011-2790: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving floating styles.
nvd
CVE-2013-2926P4MEDIUMCVSS 6.8≤ 30.0.1599.100v30.0.1599.0+72 more2013-10-16
CVE-2013-2926 [MEDIUM] CWE-399 CVE-2013-2926: Use-after-free vulnerability in the IndentOutdentCommand::tryIndentingAsListItem function in core/ed
Use-after-free vulnerability in the IndentOutdentCommand::tryIndentingAsListItem function in core/editing/IndentOutdentCommand.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to list elements.
nvd
CVE-2011-3016P4MEDIUMCVSS 6.8fixed in 17.0.963.562012-02-16
CVE-2011-3016 [MEDIUM] CWE-416 CVE-2011-3016: Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving counter nodes, related to a "read-after-free" issue.
nvd
CVE-2013-6625P4MEDIUMCVSS 6.8≤ 31.0.1650.47v31.0.1650.0+42 more2013-11-13
CVE-2013-6625 [MEDIUM] CWE-399 CVE-2013-6625: Use-after-free vulnerability in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before
Use-after-free vulnerability in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of DOM range objects in circumstances that require child node removal after a (1) mutation or (2) blur event.
nvd
CVE-2015-1269P4MEDIUMCVSS 4.3≤ 43.0.2357.812015-06-26
CVE-2015-1269 [MEDIUM] CWE-254 CVE-2015-1269: The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43
The DecodeHSTSPreloadRaw function in net/http/transport_security_state.cc in Google Chrome before 43.0.2357.130 does not properly canonicalize DNS hostnames before making comparisons to HSTS or HPKP preload entries, which allows remote attackers to bypass intended access restrictions via a string that (1) ends in a . (dot) character or (2) is not enti
nvd
CVE-2014-7936P4MEDIUMCVSS 6.8≤ 40.0.2214.852015-01-22
CVE-2014-7936 [MEDIUM] CVE-2014-7936: Use-after-free vulnerability in the ZoomBubbleView::Close function in browser/ui/views/location_bar/
Use-after-free vulnerability in the ZoomBubbleView::Close function in browser/ui/views/location_bar/zoom_bubble_view.cc in the Views implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document that triggers improper maintenance of a zoom bubble.
nvd
CVE-2015-6776P4MEDIUMCVSS 6.8≤ 46.0.2490.862015-12-06
CVE-2015-6776 [MEDIUM] CWE-119 CVE-2015-6776: The opj_dwt_decode_1* functions in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 47.0
The opj_dwt_decode_1* functions in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 47.0.2526.73, allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data that is mishandled during a discrete wavelet transform.
nvd
CVE-2011-2788P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2788 [MEDIUM] CWE-120 CVE-2011-2788: Buffer overflow in the inspector serialization functionality in Google Chrome before 13.0.782.107 al
Buffer overflow in the inspector serialization functionality in Google Chrome before 13.0.782.107 allows user-assisted remote attackers to have an unspecified impact via unknown vectors.
nvd