cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 230 of 292
CVE-2020-6516P4MEDIUMCVSS 4.3fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6516 [MEDIUM] CVE-2020-6516: Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-21217P4MEDIUMCVSS 5.5fixed in 90.0.4430.72≥ unspecified, < 90.0.4430.722021-04-26
CVE-2021-21217 [MEDIUM] CWE-252 CVE-2021-21217: Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obt Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
nvd
CVE-2026-17872P4MEDIUMCVSS 6.1fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17872 [MEDIUM] CWE-347 CVE-2026-17872: Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a lo Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2015-1268P4MEDIUMCVSS 5.0≤ 43.0.2357.812015-06-26
CVE-2015-1268 [MEDIUM] CWE-254 CVE-2015-1268: bindings/scripts/v8_types.py in Blink, as used in Google Chrome before 43.0.2357.130, does not prope bindings/scripts/v8_types.py in Blink, as used in Google Chrome before 43.0.2357.130, does not properly select a creation context for a return value's DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code, as demonstrated by use of a data: URL.
nvd
CVE-2015-1210P4MEDIUMCVSS 5.0fixed in 40.0.2214.109fixed in 40.0.2214.1112015-02-06
CVE-2015-1210 [MEDIUM] CVE-2015-1210: The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider frame access restrictions during the throwing of an exception, which allows remote attackers to bypass
nvd
CVE-2016-1692P4MEDIUMCVSS 5.3≤ 50.0.2661.1022016-06-05
CVE-2016-1692 [MEDIUM] CWE-284 CVE-2016-1692: WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63 WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
nvd
CVE-2016-1694P4MEDIUMCVSS 5.3≤ 50.0.2661.1022016-06-05
CVE-2016-1694 [MEDIUM] CWE-284 CVE-2016-1694: browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pin browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an arbitrary recognized Certification Authority.
nvd
CVE-2015-1300P4MEDIUMCVSS 5.0≤ 44.0.24032015-09-03
CVE-2015-1300 [MEDIUM] CWE-254 CVE-2015-1300: The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext The FrameFetchContext::updateTimingInfoForIFrameNavigation function in core/loader/FrameFetchContext.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to obtain sensitive information via crafted JavaScript code that leverages a hist
nvd
CVE-2018-16075P4MEDIUMCVSS 5.3fixed in 69.0.3497.81≥ unspecified, < 69.0.3497.812019-06-27
CVE-2018-16075 [MEDIUM] CVE-2018-16075: Insufficient file type enforcement in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote Insufficient file type enforcement in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain local file data via a crafted HTML page.
nvd
CVE-2014-1748P4MEDIUMCVSS 5.0≤ 35.0.1916.113v35.0.1916.0+78 more2014-05-21
CVE-2014-1748 [MEDIUM] CVE-2014-1748: The ScrollView::paint function in platform/scroll/ScrollView.cpp in Blink, as used in Google Chrome The ScrollView::paint function in platform/scroll/ScrollView.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to spoof the UI by extending scrollbar painting into the parent frame.
nvd
CVE-2019-13660P4MEDIUMCVSS 5.3fixed in 77.0.3865.75≥ unspecified, < 77.0.3865.752019-11-25
CVE-2019-13660 [MEDIUM] CVE-2019-13660: UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof no UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a crafted HTML page.
nvd
CVE-2015-1267P4MEDIUMCVSS 5.0≤ 43.0.2357.812015-06-26
CVE-2015-1267 [MEDIUM] CWE-254 CVE-2015-1267: Blink, as used in Google Chrome before 43.0.2357.130, does not properly restrict the creation contex Blink, as used in Google Chrome before 43.0.2357.130, does not properly restrict the creation context during creation of a DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that uses a Blink public API, related to WebArrayBufferConverter.cpp, WebBlob.cpp, WebDOMError.cpp, and WebDOMFileSystem.cpp.
nvd
CVE-2015-1266P4MEDIUMCVSS 5.0≤ 43.0.2357.812015-06-26
CVE-2015-1266 [MEDIUM] CWE-254 CVE-2015-1266: content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome before 43.0.2357.130 doe content/browser/webui/content_web_ui_controller_factory.cc in Google Chrome before 43.0.2357.130 does not properly consider the scheme in determining whether a URL is associated with a WebUI SiteInstance, which allows remote attackers to bypass intended access restrictions via a similar URL, as demonstrated by use of http://gpu when there is a WebUI c
nvd
CVE-2022-4910P4MEDIUMCVSS 5.4fixed in 107.0.5304.62≥ 107.0.5304.62, < 107.0.5304.622023-07-29
CVE-2022-4910 [MEDIUM] CVE-2022-4910: Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2021-21200P4MEDIUMCVSS 5.4fixed in 89.0.4389.72≥ unspecified, < 89.0.4389.722023-01-02
CVE-2021-21200 [MEDIUM] CWE-125 CVE-2021-21200: Out of bounds read in WebUI Settings in Google Chrome prior to 89.0.4389.72 allowed a remote attacke Out of bounds read in WebUI Settings in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chrome security severity: Low)
nvd
CVE-2010-1237P4HIGHCVSS 7.5v4.1.249.0v4.1.249.1001+31 more2010-04-01
CVE-2010-1237 [HIGH] CWE-20 CVE-2010-1237: Google Chrome 4.1 BETA before 4.1.249.1036 allows remote attackers to cause a denial of service (mem Google Chrome 4.1 BETA before 4.1.249.1036 allows remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via an empty SVG element.
nvd
CVE-2025-3074P4MEDIUMCVSS 5.4fixed in 135.0.7049.52≥ 135.0.7049.52, < 135.0.7049.522025-04-02
CVE-2025-3074 [MEDIUM] CWE-451 CVE-2025-3074: Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote a Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-5281P4MEDIUMCVSS 5.4fixed in 137.0.7151.55≥ 137.0.7151.55, < 137.0.7151.552025-05-27
CVE-2025-5281 [MEDIUM] CWE-200 CVE-2025-5281: Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote att Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2025-12906P4MEDIUMCVSS 5.4fixed in 140.0.7339.80≥ 140.0.7339.80, < 140.0.7339.802025-11-08
CVE-2025-12906 [MEDIUM] CWE-693 CVE-2025-12906: Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-8539P4MEDIUMCVSS 5.4fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8539 [MEDIUM] CWE-94 CVE-2026-8539: Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remot Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase