cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 220 of 292
CVE-2012-5117P4HIGHCVSS 7.5≤ 23.0.1271.62v23.0.1271.0+52 more2012-11-07
CVE-2012-5117 [HIGH] CWE-264 CVE-2012-5117: Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in th Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecified impact and remote attack vectors.
nvd
CVE-2026-17812P4MEDIUMCVSS 5.4fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17812 [MEDIUM] CWE-451 CVE-2026-17812: Inappropriate implementation in DigitalCredentials in Google Chrome prior to 151.0.7922.72 allowed a Inappropriate implementation in DigitalCredentials in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7998P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7998 [MEDIUM] CWE-20 CVE-2026-7998: Insufficient validation of untrusted input in Dialog in Google Chrome prior to 148.0.7778.96 allowed Insufficient validation of untrusted input in Dialog in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-0901P4MEDIUMCVSS 5.4fixed in 144.0.7559.59≥ 144.0.7559.59, < 144.0.7559.592026-01-20
CVE-2026-0901 [MEDIUM] CWE-451 CVE-2026-0901: Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a r Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17728P4MEDIUMCVSS 5.4≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17728 [MEDIUM] CWE-79 CVE-2026-17728: Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17734P4MEDIUMCVSS 5.4≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17734 [MEDIUM] CWE-79 CVE-2026-17734: Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-3063P4MEDIUMCVSS 5.4fixed in 145.0.7632.116fixed in 145.0.7632.117+1 more2026-02-23
CVE-2026-3063 [MEDIUM] CVE-2026-3063: Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacke Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via DevTools. (Chromium security severity: High)
nvd
CVE-2025-12908P4MEDIUMCVSS 5.4fixed in 140.0.7339.80≥ 140.0.7339.80, < 140.0.7339.802025-11-08
CVE-2025-12908 [MEDIUM] CWE-20 CVE-2025-12908: Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7 Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14132P4MEDIUMCVSS 5.4fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14132 [MEDIUM] CWE-451 CVE-2026-14132: Inappropriate implementation in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attac Inappropriate implementation in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14142P4MEDIUMCVSS 5.4fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14142 [MEDIUM] CWE-1021 CVE-2026-14142: Inappropriate implementation in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote Inappropriate implementation in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-0904P4MEDIUMCVSS 5.4fixed in 144.0.7559.59fixed in 144.0.7559.60+1 more2026-01-20
CVE-2026-0904 [MEDIUM] CWE-451 CVE-2026-0904: Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.7559.59 allowed a remot Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-6555P4MEDIUMCVSS 5.4fixed in 138.0.7204.49≥ 138.0.7204.49, < 138.0.7204.492025-06-24
CVE-2025-6555 [MEDIUM] CWE-416 CVE-2025-6555: Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to pot Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-16415P4MEDIUMCVSS 5.4fixed in 150.0.7871.182≥ 150.0.7871.182, < 150.0.7871.1822026-07-21
CVE-2026-16415 [MEDIUM] CWE-20 CVE-2026-16415: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 al Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-13097P4MEDIUMCVSS 5.4fixed in 136.0.7103.59fixed in 136.0.7103.48+1 more2025-11-14
CVE-2025-13097 [MEDIUM] CWE-79 CVE-2025-13097: Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote at Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-3953P4HIGHCVSS 7.5fixed in 17.0.963.462012-02-09
CVE-2011-3953 [HIGH] CVE-2011-3953: Google Chrome before 17.0.963.46 does not prevent monitoring of the clipboard after a paste event, w Google Chrome before 17.0.963.46 does not prevent monitoring of the clipboard after a paste event, which has unspecified impact and remote attack vectors.
nvd
CVE-2026-5895P4MEDIUMCVSS 5.4fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5895 [MEDIUM] CWE-451 CVE-2026-5895: Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote att Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low)
nvd
CVE-2026-8003P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8003 [MEDIUM] CWE-20 CVE-2026-8003: Insufficient validation of untrusted input in TabGroups in Google Chrome prior to 148.0.7778.96 allo Insufficient validation of untrusted input in TabGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2026-7958P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7958 [MEDIUM] CWE-79 CVE-2026-7958: Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed an att Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2011-3879P4HIGHCVSS 7.5fixed in 15.0.874.1022011-10-25
CVE-2011-3879 [HIGH] CVE-2011-3879: Google Chrome before 15.0.874.102 does not prevent redirects to chrome: URLs, which has unspecified Google Chrome before 15.0.874.102 does not prevent redirects to chrome: URLs, which has unspecified impact and remote attack vectors.
nvd
CVE-2024-9966P4MEDIUMCVSS 5.3fixed in 130.0.6723.58≥ 130.0.6723.58, < 130.0.6723.582024-10-15
CVE-2024-9966 [MEDIUM] CVE-2024-9966: Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
nvd
Google Chrome vulnerabilities | cvebase