cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 225 of 292
CVE-2018-16086P4MEDIUMCVSS 5.4fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-06-27
CVE-2018-16086 [MEDIUM] CWE-285 CVE-2018-16086: Insufficient policy enforcement in extensions API in Google Chrome prior to 69.0.3497.81 allowed an Insufficient policy enforcement in extensions API in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2011-2830P4HIGHCVSS 7.5fixed in 14.0.835.1632011-10-28
CVE-2011-2830 [HIGH] CVE-2011-2830: Google V8, as used in Google Chrome before 14.0.835.163, does not properly implement script object w Google V8, as used in Google Chrome before 14.0.835.163, does not properly implement script object wrappers, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2010-3112P4CRITICALCVSS 10.0fixed in 5.0.375.1272010-08-24
CVE-2010-3112 [CRITICAL] CWE-119 CVE-2010-3112: Google Chrome before 5.0.375.127 does not properly implement file dialogs, which allows attackers to Google Chrome before 5.0.375.127 does not properly implement file dialogs, which allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2019-13680P4MEDIUMCVSS 5.3fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13680 [MEDIUM] CVE-2019-13680: Inappropriate implementation in TLS in Google Chrome prior to 77.0.3865.75 allowed a remote attacker Inappropriate implementation in TLS in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof client IP address to websites via crafted TLS connections.
nvd
CVE-2025-5067P4MEDIUMCVSS 5.4fixed in 137.0.7151.55≥ 137.0.7151.55, < 137.0.7151.552025-05-27
CVE-2025-5067 [MEDIUM] CWE-290 CVE-2025-5067: Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote a Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2011-2828P4HIGHCVSS 7.5fixed in 13.0.782.2152011-08-29
CVE-2011-2828 [HIGH] CWE-787 CVE-2011-2828: Google V8, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial o Google V8, as used in Google Chrome before 13.0.782.215, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.
nvd
CVE-2026-17932P4MEDIUMCVSS 5.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17932 [MEDIUM] CWE-416 CVE-2026-17932: Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local at Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-8586P4MEDIUMCVSS 5.5fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8586 [MEDIUM] CWE-284 CVE-2026-8586: Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass discretionary access control via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2025-0996P4MEDIUMCVSS 5.4fixed in 133.0.6943.98≥ 133.0.6943.98, < 133.0.6943.982025-02-15
CVE-2025-0996 [MEDIUM] CWE-1007 CVE-2025-0996: Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowe Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2012-2900P4HIGHCVSS 7.5≤ 22.0.1229.91v22.0.1229.0+54 more2012-10-09
CVE-2012-2900 [HIGH] CVE-2012-2900: Skia, as used in Google Chrome before 22.0.1229.92, does not properly render text, which allows remo Skia, as used in Google Chrome before 22.0.1229.92, does not properly render text, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3955P4HIGHCVSS 7.5fixed in 17.0.963.462012-02-09
CVE-2011-3955 [HIGH] CVE-2011-3955: Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application c Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors that trigger the aborting of an IndexedDB transaction.
nvd
CVE-2010-4039P4CRITICALCVSS 9.8fixed in 7.0.517.412010-10-21
CVE-2010-4039 [CRITICAL] CVE-2010-4039: Google Chrome before 7.0.517.41 on Linux does not properly set the PATH environment variable, which Google Chrome before 7.0.517.41 on Linux does not properly set the PATH environment variable, which has unspecified impact and attack vectors.
nvd
CVE-2025-3072P4MEDIUMCVSS 5.4fixed in 135.0.7049.52≥ 135.0.7049.52, < 135.0.7049.522025-04-02
CVE-2025-3072 [MEDIUM] CWE-451 CVE-2025-3072: Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-3073P4MEDIUMCVSS 5.4fixed in 135.0.7049.52≥ 135.0.7049.52, < 135.0.7049.522025-04-02
CVE-2025-3073 [MEDIUM] CWE-451 CVE-2025-3073: Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2011-2837P4HIGHCVSS 7.5fixed in 14.0.835.1632011-09-19
CVE-2011-2837 [HIGH] CVE-2011-2837: Google Chrome before 14.0.835.163 on Linux does not use the PIC and PIE compiler options for positio Google Chrome before 14.0.835.163 on Linux does not use the PIC and PIE compiler options for position-independent code, which has unspecified impact and attack vectors.
nvd
CVE-2025-3071P4MEDIUMCVSS 5.4fixed in 135.0.7049.52≥ 135.0.7049.52, < 135.0.7049.522025-04-02
CVE-2025-3071 [MEDIUM] CWE-346 CVE-2025-3071: Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-10984P4MEDIUMCVSS 5.4fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10984 [MEDIUM] CWE-451 CVE-2026-10984: Inappropriate implementation in Accessibility in Google Chrome on Android prior to 149.0.7827.53 all Inappropriate implementation in Accessibility in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-7931P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7931 [MEDIUM] CWE-20 CVE-2026-7931: Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.96 all Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-7935P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7935 [MEDIUM] CWE-451 CVE-2026-7935: Inappropriate implementation in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote atta Inappropriate implementation in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-8561P4MEDIUMCVSS 5.4fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8561 [MEDIUM] CWE-451 CVE-2026-8561: Incorrect security UI in Fullscreen in Google Chrome prior to 148.0.7778.168 allowed a remote attack Incorrect security UI in Fullscreen in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase