Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 221 of 292
CVE-2013-0908P4HIGHCVSS 7.5≤ 25.0.1364.126v25.0.1364.0+104 more2013-03-05
CVE-2013-0908 [HIGH] CVE-2013-0908: Google Chrome before 25.0.1364.152 does not properly manage bindings of extension processes, which h
Google Chrome before 25.0.1364.152 does not properly manage bindings of extension processes, which has unspecified impact and attack vectors.
nvd
CVE-2026-7955P4MEDIUMCVSS 5.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7955 [MEDIUM] CWE-457 CVE-2026-7955: Uninitialized Use in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had c
Uninitialized Use in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2026-14391P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14391 [MEDIUM] CWE-472 CVE-2026-14391: Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attack
Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-5886P4MEDIUMCVSS 5.3fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5886 [MEDIUM] CWE-125 CVE-2026-5886: Out of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attac
Out of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13874P4MEDIUMCVSS 5.3fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13874 [MEDIUM] CWE-362 CVE-2026-13874: Race in DataTransfer in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain pot
Race in DataTransfer in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11174P4MEDIUMCVSS 5.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11174 [MEDIUM] CWE-693 CVE-2026-11174: Inappropriate implementation in Site Isolation in Google Chrome prior to 149.0.7827.53 allowed a rem
Inappropriate implementation in Site Isolation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8020P4MEDIUMCVSS 5.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8020 [MEDIUM] CWE-457 CVE-2026-8020: Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacke
Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14012P4MEDIUMCVSS 5.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14012 [MEDIUM] CWE-1300 CVE-2026-14012: Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote att
Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8541P4MEDIUMCVSS 5.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8541 [MEDIUM] CWE-125 CVE-2026-8541: Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had
Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8546P4MEDIUMCVSS 5.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8546 [MEDIUM] CWE-125 CVE-2026-8546: Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remo
Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13989P4MEDIUMCVSS 5.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13989 [MEDIUM] CWE-451 CVE-2026-13989: Inappropriate implementation in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote at
Inappropriate implementation in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11696P4MEDIUMCVSS 5.3fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11696 [MEDIUM] CWE-457 CVE-2026-11696: Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote atta
Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8582P4MEDIUMCVSS 5.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8582 [MEDIUM] CWE-664 CVE-2026-8582: Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to
Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-12033P4MEDIUMCVSS 5.3fixed in 149.0.7827.115≥ 149.0.7827.115, < 149.0.7827.1152026-06-11
CVE-2026-12033 [MEDIUM] CWE-125 CVE-2026-12033: Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacke
Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13023P4MEDIUMCVSS 5.3fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13023 [MEDIUM] CWE-457 CVE-2026-13023: Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had
Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5890P4MEDIUMCVSS 5.3fixed in 147.0.7727.55≥ 147.0.7727.55, < 147.0.7727.552026-04-08
CVE-2026-5890 [MEDIUM] CWE-362 CVE-2026-5890: Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potent
Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8583P4MEDIUMCVSS 5.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8583 [MEDIUM] CWE-693 CVE-2026-8583: Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 148.0.7778.168 allowed
Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11678P4MEDIUMCVSS 5.3fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11678 [MEDIUM] CWE-472 CVE-2026-11678: Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who ha
Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7960P4MEDIUMCVSS 5.3fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7960 [MEDIUM] CWE-362 CVE-2026-7960: Race in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised
Race in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
cvelistv5nvd
CVE-2011-0781P4HIGHCVSS 7.5fixed in 9.0.597.842011-02-04
CVE-2011-0781 [HIGH] CWE-20 CVE-2011-0781: Google Chrome before 9.0.597.84 does not properly handle autofill profile merging, which has unspeci
Google Chrome before 9.0.597.84 does not properly handle autofill profile merging, which has unspecified impact and remote attack vectors.
nvd