cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 226 of 292
CVE-2024-0333P4MEDIUMCVSS 5.3fixed in 120.0.6099.216≥ 120.0.6099.216, < 120.0.6099.2162024-01-10
CVE-2024-0333 [MEDIUM] CVE-2024-0333: Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attac Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11701P4MEDIUMCVSS 5.4fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11701 [MEDIUM] CWE-20 CVE-2026-11701: Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13977P4MEDIUMCVSS 5.4fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13977 [MEDIUM] CWE-79 CVE-2026-13977: Inappropriate implementation in HTMLParser in Google Chrome prior to 150.0.7871.47 allowed a remote Inappropriate implementation in HTMLParser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2012-2892P4MEDIUMCVSS 5.0≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2892 [MEDIUM] CVE-2012-2892: Unspecified vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to bypass the Unspecified vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to bypass the pop-up blocker via unknown vectors.
nvd
CVE-2026-7939P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7939 [MEDIUM] CWE-79 CVE-2026-7939: Inappropriate implementation in SanitizerAPI in Google Chrome prior to 148.0.7778.96 allowed a remot Inappropriate implementation in SanitizerAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-6556P4MEDIUMCVSS 5.4fixed in 138.0.7204.49≥ 138.0.7204.49, < 138.0.7204.492025-06-24
CVE-2025-6556 [MEDIUM] CWE-288 CVE-2025-6556: Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote a Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2011-3102P4MEDIUMCVSS 6.8≤ 19.0.1084.452012-05-16
CVE-2011-3102 [MEDIUM] CWE-189 CVE-2011-3102: Off-by-one error in libxml2, as used in Google Chrome before 19.0.1084.46 and other products, allows Off-by-one error in libxml2, as used in Google Chrome before 19.0.1084.46 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2026-9971P4MEDIUMCVSS 5.4fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9971 [MEDIUM] CWE-79 CVE-2026-9971: Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8019P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8019 [MEDIUM] CWE-451 CVE-2026-8019: Insufficient policy enforcement in WebApp in Google Chrome prior to 148.0.7778.96 allowed a remote a Insufficient policy enforcement in WebApp in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-12905P4MEDIUMCVSS 5.4fixed in 140.0.7339.80≥ 140.0.7339.80, < 140.0.7339.802025-11-08
CVE-2025-12905 [MEDIUM] CWE-346 CVE-2025-12905: Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11243P4MEDIUMCVSS 5.4fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11243 [MEDIUM] CWE-346 CVE-2026-11243: Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote a Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11232P4MEDIUMCVSS 5.4fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11232 [MEDIUM] CWE-451 CVE-2026-11232: Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote a Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2010-1500P4HIGHCVSS 7.5≤ 4.1.249.1058v1.0.154.53+232 more2010-04-23
CVE-2010-1500 [HIGH] CVE-2010-1500: Google Chrome before 4.1.249.1059 does not properly support forms, which has unknown impact and atta Google Chrome before 4.1.249.1059 does not properly support forms, which has unknown impact and attack vectors, related to a "type confusion error."
nvd
CVE-2026-8008P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8008 [MEDIUM] CWE-451 CVE-2026-8008: Inappropriate implementation in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker Inappropriate implementation in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2026-8006P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8006 [MEDIUM] CWE-451 CVE-2026-8006: Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attac Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2013-0838P4HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2013-0838 [HIGH] CWE-264 CVE-2013-0838: Google Chrome before 24.0.1312.52 on Linux uses weak permissions for shared memory segments, which h Google Chrome before 24.0.1312.52 on Linux uses weak permissions for shared memory segments, which has unspecified impact and attack vectors.
nvd
CVE-2012-5154P4HIGHCVSS 7.5≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5154 [HIGH] CWE-189 CVE-2012-5154: Integer overflow in Google Chrome before 24.0.1312.52 on Windows allows attackers to cause a denial Integer overflow in Google Chrome before 24.0.1312.52 on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via vectors related to allocation of shared memory.
nvd
CVE-2015-1229P4MEDIUMCVSS 5.0≤ 40.0.2214.1152015-03-09
CVE-2015-1229 [MEDIUM] CWE-19 CVE-2015-1229: net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.
nvd
CVE-2026-13030P4MEDIUMCVSS 5.3fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13030 [MEDIUM] CWE-457 CVE-2026-13030: Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attack Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11145P4MEDIUMCVSS 5.3fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11145 [MEDIUM] CWE-362 CVE-2026-11145: Race in Geolocation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to Race in Geolocation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase