Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 217 of 292
CVE-2013-6622P4MEDIUMCVSS 6.8≤ 31.0.1650.47v31.0.1650.0+42 more2013-11-13
CVE-2013-6622 [MEDIUM] CWE-399 CVE-2013-6622: Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTM
Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the movement of a media element between documents.
nvd
CVE-2013-2911P4MEDIUMCVSS 6.8≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2911 [MEDIUM] CWE-399 CVE-2013-2911: Use-after-free vulnerability in the XSLStyleSheet::compileStyleSheet function in core/xml/XSLStyleSh
Use-after-free vulnerability in the XSLStyleSheet::compileStyleSheet function in core/xml/XSLStyleSheetLibxslt.cpp in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of post-failure recompilation in unspecified libxslt ve
nvd
CVE-2013-2913P4MEDIUMCVSS 6.8≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2913 [MEDIUM] CWE-399 CVE-2013-2913: Use-after-free vulnerability in the XMLDocumentParser::append function in core/xml/parser/XMLDocumen
Use-after-free vulnerability in the XMLDocumentParser::append function in core/xml/parser/XMLDocumentParser.cpp in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an XML document.
nvd
CVE-2026-17913P4UNKNOWN≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17913 CVE-2026-17913: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2010-4036P4MEDIUMCVSS 6.8≤ 7.0.517.40v6.0.454.0+177 more2010-10-21
CVE-2010-4036 [MEDIUM] CWE-20 CVE-2010-4036: Google Chrome before 7.0.517.41 does not properly handle the unloading of a page, which allows remot
Google Chrome before 7.0.517.41 does not properly handle the unloading of a page, which allows remote attackers to spoof URLs via unspecified vectors.
nvd
CVE-2010-3258P4CRITICALCVSS 9.3fixed in 6.0.472.532010-09-07
CVE-2010-3258 [CRITICAL] CWE-502 CVE-2010-3258: The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize paramete
The sandbox implementation in Google Chrome before 6.0.472.53 does not properly deserialize parameters, which has unspecified impact and remote attack vectors.
nvd
CVE-2011-3019P4MEDIUMCVSS 6.8fixed in 17.0.963.562012-02-16
CVE-2011-3019 [MEDIUM] CWE-787 CVE-2011-3019: Heap-based buffer overflow in Google Chrome before 17.0.963.56 allows remote attackers to cause a de
Heap-based buffer overflow in Google Chrome before 17.0.963.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska video (aka MKV) file.
nvd
CVE-2010-2650P4CRITICALCVSS 9.3fixed in 5.0.375.992010-07-06
CVE-2010-2650 [CRITICAL] CVE-2010-2650: Unspecified vulnerability in Google Chrome before 5.0.375.99 has unknown impact and attack vectors,
Unspecified vulnerability in Google Chrome before 5.0.375.99 has unknown impact and attack vectors, related to an "annoyance with print dialogs."
nvd
CVE-2016-1702P4MEDIUMCVSS 6.5≤ 51.0.2704.632016-06-05
CVE-2016-1702 [MEDIUM] CWE-119 CVE-2016-1702: The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before
The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serialized data.
nvd
CVE-2016-5130P4MEDIUMCVSS 6.5≤ 51.0.2704.1062016-07-23
CVE-2016-5130 [MEDIUM] CWE-284 CVE-2016-5130: content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restri
content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, which allows remote attackers to spoof the URL display via a crafted web site.
nvd
CVE-2016-1707P4MEDIUMCVSS 6.5≤ 51.0.2704.1062016-07-23
CVE-2016-1707 [MEDIUM] CWE-20 CVE-2016-1707: ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensu
ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensure that an invalid URL is replaced with the about:blank URL, which allows remote attackers to spoof the URL display via a crafted web site.
nvd
CVE-2016-5189P4MEDIUMCVSS 6.5≤ 53.0.2785.1432016-12-18
CVE-2016-5189 [MEDIUM] CWE-284 CVE-2016-5189: Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted
Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted navigation to blob URLs with non-canonical origins, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via crafted HTML pages.
nvd
CVE-2010-4199P4HIGHCVSS 8.8fixed in 7.0.517.442010-11-06
CVE-2010-4199 [HIGH] CWE-20 CVE-2010-4199: Google Chrome before 7.0.517.44 does not properly perform a cast of an unspecified variable during p
Google Chrome before 7.0.517.44 does not properly perform a cast of an unspecified variable during processing of an SVG use element, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SVG document.
nvd
CVE-2016-5191P4MEDIUMCVSS 6.1≤ 53.0.2785.1432016-12-18
CVE-2016-5191 [MEDIUM] CWE-79 CVE-2016-5191: Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 f
Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation of supplied data, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via crafted HTML pages, as demonstrated by an interpretation conflict between userinfo and scheme in an http://javascript:
nvd
CVE-2010-3917P4MEDIUMCVSS 6.5fixed in 3.0vbefore 3.02020-02-06
CVE-2010-3917 [MEDIUM] CWE-200 CVE-2010-3917: Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to ob
Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to obtain sensitive information via a crafted web site.
nvd
CVE-2019-5855P4MEDIUMCVSS 6.5fixed in 76.0.3809.87≥ unspecified, < 76.0.3809.872019-11-25
CVE-2019-5855 [MEDIUM] CWE-190 CVE-2019-5855: Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to poten
Integer overflow in PDFium in Google Chrome prior to 76.0.3809.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2019-5867P4MEDIUMCVSS 6.5fixed in 76.0.3809.100≥ unspecified, < 76.0.3809.1002019-11-25
CVE-2019-5867 [MEDIUM] CWE-125 CVE-2019-5867: Out of bounds read in JavaScript in Google Chrome prior to 76.0.3809.100 allowed a remote attacker t
Out of bounds read in JavaScript in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2011-2353P4MEDIUMCVSS 6.5vbefore Blink M132019-11-07
CVE-2011-2353 [MEDIUM] CWE-416 CVE-2011-2353: Use after free vulnerability in documentloader in WebKit in Google Chrome before Blink M13 in Docume
Use after free vulnerability in documentloader in WebKit in Google Chrome before Blink M13 in DocumentWriter::replaceDocument function.
nvd
CVE-2011-1802P4MEDIUMCVSS 6.5vbefore Blink M11 and M122019-11-12
CVE-2011-1802 [MEDIUM] CWE-476 CVE-2011-1802: WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allow
WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption).
nvd
CVE-2011-2334P4MEDIUMCVSS 6.5vbefore Blink M122019-11-12
CVE-2011-2334 [MEDIUM] CWE-416 CVE-2011-2334: Use after free vulnerability exists in WebKit in Google Chrome before Blink M12 in RenderLayerwhen r
Use after free vulnerability exists in WebKit in Google Chrome before Blink M12 in RenderLayerwhen removing elements with reflections.
nvd