Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 219 of 292
CVE-2021-30539P4MEDIUMCVSS 5.4fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30539 [MEDIUM] CWE-863 CVE-2021-30539: Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 al
Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2017-15423P4MEDIUMCVSS 5.3fixed in 63.0.3239.842018-08-28
CVE-2017-15423 [MEDIUM] CWE-310 CVE-2017-15423: Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a re
Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the low-order bits of SHA512(password) by inspecting protocol traffic.
nvd
CVE-2009-1412P4HIGHCVSS 7.8≤ 1.0.154.53v0.2.149.29+14 more2009-04-24
CVE-2009-1412 [HIGH] CWE-200 CVE-2009-1412: Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154
Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows remote attackers to determine the existence of files, and open tabs for URLs that do not satisfy the IsWebSafeScheme restriction, via a web page that sets document.location to a chromehtml: value, as demonstr
nvd
CVE-2011-1199P4HIGHCVSS 7.5fixed in 10.0.648.1272011-03-11
CVE-2011-1199 [HIGH] CVE-2011-1199: Google Chrome before 10.0.648.127 does not properly handle DataView objects, which allows remote att
Google Chrome before 10.0.648.127 does not properly handle DataView objects, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-1254P4MEDIUMCVSS 5.0≤ 42.0.2311.1522015-05-20
CVE-2015-1254 [MEDIUM] CWE-264 CVE-2015-1254: core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritanc
core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by leveraging the availability of editing.
nvd
CVE-2022-3201P4MEDIUMCVSS 5.4fixed in 105.0.5195.125≥ unspecified, < 105.0.5195.1252022-09-26
CVE-2022-3201 [MEDIUM] CWE-20 CVE-2022-3201: Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.
Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4359P4MEDIUMCVSS 5.3fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4359 [MEDIUM] CVE-2023-4359: Inappropriate implementation in App Launcher in Google Chrome on iOS prior to 116.0.5845.96 allowed
Inappropriate implementation in App Launcher in Google Chrome on iOS prior to 116.0.5845.96 allowed a remote attacker to potentially spoof elements of the security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2012-5153P4HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5153 [HIGH] CWE-119 CVE-2012-5153: Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, allows remote attackers to
Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds access to stack memory.
nvd
CVE-2012-5127P4HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5127 [HIGH] CWE-189 CVE-2012-5127: Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of s
Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted WebP image.
nvd
CVE-2013-0841P4HIGHCVSS 7.5≤ 24.0.1312.55v24.0.1272.0+114 more2013-01-24
CVE-2013-0841 [HIGH] CWE-20 CVE-2013-0841: Array index error in the content-blocking functionality in Google Chrome before 24.0.1312.56 allows
Array index error in the content-blocking functionality in Google Chrome before 24.0.1312.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2025-5064P4MEDIUMCVSS 5.4fixed in 137.0.7151.55≥ 137.0.7151.55, < 137.0.7151.552025-05-27
CVE-2025-5064 [MEDIUM] CWE-200 CVE-2025-5064: Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed
Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-9867P4MEDIUMCVSS 5.4fixed in 140.0.7339.80≥ 140.0.7339.80, < 140.0.7339.802025-09-03
CVE-2025-9867 [MEDIUM] CWE-451 CVE-2025-9867: Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed
Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-9865P4MEDIUMCVSS 5.4fixed in 140.0.7339.80≥ 140.0.7339.80, < 140.0.7339.802025-09-03
CVE-2025-9865 [MEDIUM] CWE-451 CVE-2025-9865: Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-12435P4MEDIUMCVSS 5.4fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12435 [MEDIUM] CWE-285 CVE-2025-12435: Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote
Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-2322P4MEDIUMCVSS 5.4fixed in 145.0.7632.45≥ 145.0.7632.45, < 145.0.7632.452026-02-11
CVE-2026-2322 [MEDIUM] CWE-451 CVE-2026-2322: Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote
Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-13632P4MEDIUMCVSS 5.4fixed in 143.0.7499.40≥ 143.0.7499.41, < 143.0.7499.412025-12-02
CVE-2025-13632 [MEDIUM] CWE-194 CVE-2025-13632: Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker
Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)
nvd
CVE-2026-17779P4MEDIUMCVSS 5.4fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17779 [MEDIUM] CWE-693 CVE-2026-17779: Inappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a rem
Inappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-11210P4MEDIUMCVSS 5.4fixed in 141.0.7390.54≥ 141.0.7390.54, < 141.0.7390.542025-11-06
CVE-2025-11210 [MEDIUM] CWE-1300 CVE-2025-11210: Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote att
Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11666P4MEDIUMCVSS 5.4fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11666 [MEDIUM] CWE-20 CVE-2026-11666: Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed
Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17874P4MEDIUMCVSS 5.4fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17874 [MEDIUM] CWE-451 CVE-2026-17874: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd