cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82

Vulnerabilities

Page 23 of 292
CVE-2026-11060P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11060 [HIGH] CWE-416 CVE-2026-11060: Use after free in Media in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker Use after free in Media in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11136P3HIGHCVSS 8.8fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11136 [HIGH] CWE-416 CVE-2026-11136: Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9973P3HIGHCVSS 8.8fixed in 148.0.7778.216fixed in 148.0.7778.215+1 more2026-05-28
CVE-2026-9973 [HIGH] CWE-787 CVE-2026-9973: Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to exec Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8558P3HIGHCVSS 8.8fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8558 [HIGH] CWE-787 CVE-2026-8558: Out of bounds write in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to e Out of bounds write in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-8518P3HIGHCVSS 8.8fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8518 [HIGH] CWE-416 CVE-2026-8518: Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execut Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-14108P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14108 [HIGH] CWE-416 CVE-2026-14108: Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execut Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
nvd
CVE-2026-14431P3HIGHCVSS 8.8fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14431 [HIGH] CWE-843 CVE-2026-14431: Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute ar Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17751P3HIGHCVSS 8.8≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17751 [HIGH] CWE-269 CVE-2026-17751: Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote at Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17989P3HIGHCVSS 8.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17989 [HIGH] CWE-843 CVE-2026-17989: Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute ar Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11633P3HIGHCVSS 8.8fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11633 [HIGH] CWE-416 CVE-2026-11633: Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacke Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)
nvd
CVE-2026-13035P3HIGHCVSS 8.8fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13035 [HIGH] CWE-416 CVE-2026-13035: Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacke Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: High)
nvd
CVE-2026-17969P3HIGHCVSS 8.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17969 [HIGH] CWE-269 CVE-2026-17969: Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote a Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17956P3HIGHCVSS 8.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17956 [HIGH] CWE-269 CVE-2026-17956: Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17950P3HIGHCVSS 8.8fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17950 [HIGH] CWE-269 CVE-2026-17950: Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)
nvd
CVE-2021-30599P3HIGHCVSS 8.8fixed in 92.0.4515.159≥ unspecified, < 92.0.4515.1592021-08-26
CVE-2021-30599 [HIGH] CWE-843 CVE-2021-30599: Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute ar Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2026-13779P3HIGHCVSS 8.1fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13779 [HIGH] CWE-416 CVE-2026-13779: Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote at Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
nvd
CVE-2026-7347P3HIGHCVSS 8.1fixed in 147.0.7727.138≥ 147.0.7727.138, < 147.0.7727.1382026-04-28
CVE-2026-7347 [HIGH] CWE-416 CVE-2026-7347: Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to e Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
nvd
CVE-2026-11643P3HIGHCVSS 8.1fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11643 [HIGH] CWE-416 CVE-2026-11643: Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execut Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
nvd
CVE-2022-0290P3CRITICALCVSS 9.6fixed in 97.0.4692.99≥ unspecified, < 97.0.4692.992022-02-12
CVE-2022-0290 [CRITICAL] CWE-416 CVE-2022-0290: Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2023-1529P3CRITICALCVSS 9.8fixed in 111.0.5563.110≥ 111.0.5563.110, < 111.0.5563.1102023-03-21
CVE-2023-1529 [CRITICAL] CWE-787 CVE-2023-1529: Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote atta Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase