Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 229 of 292
CVE-2016-5223P4MEDIUMCVSS 6.5≤ 54.0.2840.992017-01-19
CVE-2016-5223 [MEDIUM] CWE-190 CVE-2016-5223: Integer overflow in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55
Integer overflow in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption or DoS via a crafted PDF file.
nvd
CVE-2016-1689P4MEDIUMCVSS 6.5≤ 50.0.2661.1022016-06-05
CVE-2016-1689 [MEDIUM] CWE-119 CVE-2016-1689: Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome befo
Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2011-2808P4MEDIUMCVSS 6.5vbefore Blink M132019-11-06
CVE-2011-2808 [MEDIUM] CWE-20 CVE-2011-2808: A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a ch
A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed.
nvd
CVE-2023-3742P4MEDIUMCVSS 6.8fixed in 114.0.5735.90≥ 114.0.5735.90, < 114.0.5735.902023-12-20
CVE-2023-3742 [MEDIUM] CVE-2023-3742: Insufficient policy enforcement in ADB in Google Chrome on ChromeOS prior to 114.0.5735.90 allowed a
Insufficient policy enforcement in ADB in Google Chrome on ChromeOS prior to 114.0.5735.90 allowed a local attacker to bypass device policy restrictions via physical access to the device. (Chromium security severity: High)
nvd
CVE-2013-6657P4MEDIUMCVSS 6.4≤ 33.0.1750.116v33.0.1750.0+95 more2014-02-24
CVE-2013-6657 [MEDIUM] CWE-264 CVE-2013-6657: core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.17
core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certain blocking of FORM elements within HTTP requests, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via unspecified vectors.
nvd
CVE-2016-5174P4MEDIUMCVSS 6.5≤ 53.0.2785.1012016-09-25
CVE-2016-5174 [MEDIUM] CWE-20 CVE-2016-5174: browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not
browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not process fullscreen toggle requests during a fullscreen transition, which allows remote attackers to cause a denial of service (unsuppressed popup) via a crafted web site.
nvd
CVE-2011-2807P4MEDIUMCVSS 6.5vbefore Blink M132019-11-07
CVE-2011-2807 [MEDIUM] CWE-755 CVE-2011-2807: Incorrect handling of timer information in Timer.cpp in WebKit in Google Chrome before Blink M13.
Incorrect handling of timer information in Timer.cpp in WebKit in Google Chrome before Blink M13.
nvd
CVE-2016-5148P4MEDIUMCVSS 6.1≤ 52.0.2743.1162016-09-11
CVE-2016-5148 [MEDIUM] CWE-79 CVE-2016-5148: Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on W
Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary web script or HTML via vectors related to widget updates, aka "Universal XSS (UXSS)."
nvd
CVE-2017-5045P4MEDIUMCVSS 6.1≤ 57.0.2987.75≤ 57.0.2987.1002017-04-24
CVE-2017-5045 [MEDIUM] CWE-79 CVE-2017-5045: XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for
XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed detection of a blocked iframe load, which allowed a remote attacker to brute force JavaScript variables via a crafted HTML page.
nvd
CVE-2018-6076P4MEDIUMCVSS 6.1fixed in 65.0.3325.146≥ unspecified, < 65.0.3325.1462018-11-14
CVE-2018-6076 [MEDIUM] CWE-79 CVE-2018-6076: Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 a
Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.
nvd
CVE-2016-5147P4MEDIUMCVSS 6.1≤ 52.0.2743.1162016-09-11
CVE-2016-5147 [MEDIUM] CWE-79 CVE-2016-5147: Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on L
Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles deferred page loads, which allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."
nvd
CVE-2018-6128P4MEDIUMCVSS 6.1fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-06-27
CVE-2018-6128 [MEDIUM] CWE-79 CVE-2018-6128: Incorrect URL parsing in WebKit in Google Chrome on iOS prior to 67.0.3396.62 allowed a remote attac
Incorrect URL parsing in WebKit in Google Chrome on iOS prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2019-13714P4MEDIUMCVSS 6.1fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13714 [MEDIUM] CWE-94 CVE-2019-13714: Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
nvd
CVE-2016-5226P4MEDIUMCVSS 6.1≤ 54.0.2840.992017-01-19
CVE-2016-5226 [MEDIUM] CWE-79 CVE-2016-5226: Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac executed javascript: URLs en
Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac executed javascript: URLs entered in the URL bar in the context of the current tab, which allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.
nvd
CVE-2020-16030P4MEDIUMCVSS 6.1fixed in 87.0.4280.66≥ unspecified, < 87.0.4280.662021-01-08
CVE-2020-16030 [MEDIUM] CWE-79 CVE-2020-16030: Insufficient data validation in Blink in Google Chrome prior to 87.0.4280.66 allowed a remote attack
Insufficient data validation in Blink in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
nvd
CVE-2022-0801P4MEDIUMCVSS 6.1fixed in 99.0.4844.51≥ unspecified, < 99.0.4844.512023-01-02
CVE-2022-0801 [MEDIUM] CWE-79 CVE-2022-0801: Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote
Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass XSS preventions via a crafted HTML page. (Chrome security severity: Medium)
nvd
CVE-2013-6666P4MEDIUMCVSS 5.8≤ 33.0.1750.144v33.0.1750.0+104 more2014-03-05
CVE-2013-6666 [MEDIUM] CWE-264 CVE-2013-6666: The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in
The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not verify that all headers are Cross-Origin Resource Sharing (CORS) simple headers before proceeding with a PPB_Flash.Navigate operation, which might allow remote attackers to bypass intended CORS restrictions v
nvd
CVE-2018-20071P4MEDIUMCVSS 6.1fixed in 70.0.3538.67≥ unspecified, < 70.0.3538.672019-01-09
CVE-2018-20071 [MEDIUM] CWE-79 CVE-2018-20071: Insufficiently strict origin checks during JIT payment app installation in Payments in Google Chrome
Insufficiently strict origin checks during JIT payment app installation in Payments in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to install a service worker for a domain that can host attacker controled files via a crafted HTML page.
nvd
CVE-2013-2881P4MEDIUMCVSS 5.8≤ 28.0.1500.94v28.0.1500.0+67 more2013-07-31
CVE-2013-2881 [MEDIUM] CWE-264 CVE-2013-2881: Google Chrome before 28.0.1500.95 does not properly handle frames, which allows remote attackers to
Google Chrome before 28.0.1500.95 does not properly handle frames, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2022-1132P4MEDIUMCVSS 6.1fixed in 100.0.4896.60≥ unspecified, < 100.0.4896.602022-07-23
CVE-2022-1132 [MEDIUM] CWE-863 CVE-2022-1132: Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.6
Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local attacker to bypass navigation restrictions via physical access to the device.
nvd