cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 227 of 292
CVE-2011-2834P4MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2834 [MEDIUM] CWE-415 CVE-2011-2834: Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote at Double free vulnerability in libxml2, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
nvd
CVE-2013-0828P4MEDIUMCVSS 6.8≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2013-0828 [MEDIUM] CWE-399 CVE-2013-0828: The PDF functionality in Google Chrome before 24.0.1312.52 does not properly perform a cast of an un The PDF functionality in Google Chrome before 24.0.1312.52 does not properly perform a cast of an unspecified variable during processing of the root of the structure tree, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2026-9942P4MEDIUMCVSS 5.0fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9942 [MEDIUM] CWE-457 CVE-2026-9942: Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who ha Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2011-3062P4MEDIUMCVSS 6.8fixed in 18.0.1025.1422012-03-30
CVE-2011-3062 [MEDIUM] CWE-682 CVE-2011-3062: Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attac Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted OpenType file.
nvd
CVE-2011-3066P4MEDIUMCVSS 6.8fixed in 18.0.1025.1512012-04-05
CVE-2011-3066 [MEDIUM] CWE-125 CVE-2011-3066: Skia, as used in Google Chrome before 18.0.1025.151, does not properly perform clipping, which allow Skia, as used in Google Chrome before 18.0.1025.151, does not properly perform clipping, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2026-9903P4MEDIUMCVSS 5.0fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9903 [MEDIUM] CWE-20 CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.21 Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted MHTML page. (Chromium security severity: High)
nvd
CVE-2026-9979P4MEDIUMCVSS 5.0fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9979 [MEDIUM] CWE-20 CVE-2026-9979: Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-9980P4MEDIUMCVSS 5.0fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9980 [MEDIUM] CWE-20 CVE-2026-9980: Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allo Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8009P4MEDIUMCVSS 5.0fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8009 [MEDIUM] CWE-693 CVE-2026-8009: Inappropriate implementation in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attack Inappropriate implementation in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2011-2799P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2799 [MEDIUM] CWE-416 CVE-2011-2799: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to HTML range handling.
nvd
CVE-2011-2797P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2797 [MEDIUM] CWE-416 CVE-2011-2797: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to resource caching.
nvd
CVE-2011-2351P4MEDIUMCVSS 6.8fixed in 12.0.742.1122011-06-29
CVE-2011-2351 [MEDIUM] CWE-416 CVE-2011-2351: Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements.
nvd
CVE-2011-2847P4MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2847 [MEDIUM] CWE-416 CVE-2011-2847: Use-after-free vulnerability in the document loader in Google Chrome before 14.0.835.163 allows remo Use-after-free vulnerability in the document loader in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2009-2816P4MEDIUMCVSS 6.8fixed in 3.0.195.332009-11-13
CVE-2009-2816 [MEDIUM] CWE-352 CVE-2009-2816: The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a
nvd
CVE-2011-2846P4MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2846 [MEDIUM] CWE-416 CVE-2011-2846: Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to unload event handling.
nvd
CVE-2012-2893P4MEDIUMCVSS 6.8≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2893 [MEDIUM] CWE-399 CVE-2012-2893: Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote at Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.
nvd
CVE-2011-1455P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1455 [MEDIUM] CWE-125 CVE-2011-1455: Google Chrome before 11.0.696.57 does not properly handle PDF documents with multipart encoding, whi Google Chrome before 11.0.696.57 does not properly handle PDF documents with multipart encoding, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.
nvd
CVE-2011-2818P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2818 [MEDIUM] CWE-416 CVE-2011-2818: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to display box rendering.
nvd
CVE-2011-1808P4MEDIUMCVSS 6.8fixed in 12.0.742.912011-06-09
CVE-2011-1808 [MEDIUM] CWE-416 CVE-2011-1808: Use-after-free vulnerability in Google Chrome before 12.0.742.91 allows remote attackers to cause a Use-after-free vulnerability in Google Chrome before 12.0.742.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to incorrect integer calculations during float handling.
nvd
CVE-2011-1809P4MEDIUMCVSS 6.8fixed in 12.0.742.912011-06-09
CVE-2011-1809 [MEDIUM] CWE-416 CVE-2011-1809: Use-after-free vulnerability in the accessibility feature in Google Chrome before 12.0.742.91 allows Use-after-free vulnerability in the accessibility feature in Google Chrome before 12.0.742.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
Google Chrome vulnerabilities | cvebase