Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 231 of 292
CVE-2026-8015P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8015 [MEDIUM] CWE-451 CVE-2026-8015: Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attac
Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-8012P4MEDIUMCVSS 5.4fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-8012 [MEDIUM] CWE-79 CVE-2026-8012: Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attac
Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17903P4MEDIUMCVSS 5.4fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17903 [MEDIUM] CWE-79 CVE-2026-17903: Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an att
Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment to inject scripts or HTML into a privileged page via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2011-3052P4MEDIUMCVSS 6.8fixed in 18.0.1025.1422012-03-22
CVE-2011-3052 [MEDIUM] CWE-119 CVE-2011-3052: The WebGL implementation in Google Chrome before 17.0.963.83 does not properly handle CANVAS element
The WebGL implementation in Google Chrome before 17.0.963.83 does not properly handle CANVAS elements, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-3037P4MEDIUMCVSS 6.8fixed in 17.0.963.652012-03-05
CVE-2011-3037 [MEDIUM] CWE-704 CVE-2011-3037: Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the
Google Chrome before 17.0.963.65 does not properly perform casts of unspecified variables during the splitting of anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2011-3036P4MEDIUMCVSS 6.8fixed in 17.0.963.652012-03-05
CVE-2011-3036 [MEDIUM] CWE-704 CVE-2011-3036: Google Chrome before 17.0.963.65 does not properly perform a cast of an unspecified variable during
Google Chrome before 17.0.963.65 does not properly perform a cast of an unspecified variable during handling of line boxes, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2012-2882P4MEDIUMCVSS 6.8≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2882 [MEDIUM] CWE-20 CVE-2012-2882: FFmpeg, as used in Google Chrome before 22.0.1229.79, does not properly handle OGG containers, which
FFmpeg, as used in Google Chrome before 22.0.1229.79, does not properly handle OGG containers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "wild pointer" issue.
nvd
CVE-2026-10010P4MEDIUMCVSS 5.0fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-10010 [MEDIUM] CWE-346 CVE-2026-10010: Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a
Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2011-3897P4MEDIUMCVSS 6.8fixed in 15.0.874.1202011-11-11
CVE-2011-3897 [MEDIUM] CWE-416 CVE-2011-3897: Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attack
Use-after-free vulnerability in Google Chrome before 15.0.874.120 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing.
nvd
CVE-2011-3971P4MEDIUMCVSS 6.8fixed in 17.0.963.462012-02-09
CVE-2011-3971 [MEDIUM] CWE-416 CVE-2011-3971: Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attacke
Use-after-free vulnerability in Google Chrome before 17.0.963.46 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to mousemove events.
nvd
CVE-2011-1817P4MEDIUMCVSS 6.8fixed in 12.0.742.912011-06-09
CVE-2011-1817 [MEDIUM] CWE-119 CVE-2011-1817: Google Chrome before 12.0.742.91 does not properly implement history deletion, which allows remote a
Google Chrome before 12.0.742.91 does not properly implement history deletion, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-1434P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1434 [MEDIUM] CWE-20 CVE-2011-1434: Google Chrome before 11.0.696.57 does not ensure thread safety during handling of MIME data, which a
Google Chrome before 11.0.696.57 does not ensure thread safety during handling of MIME data, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-2828P4MEDIUMCVSS 6.8≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2828 [MEDIUM] CWE-189 CVE-2012-2828: Multiple integer overflows in the PDF functionality in Google Chrome before 20.0.1132.43 allow remot
Multiple integer overflows in the PDF functionality in Google Chrome before 20.0.1132.43 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2012-2832P4MEDIUMCVSS 6.8≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2832 [MEDIUM] CVE-2012-2832: The image-codec implementation in the PDF functionality in Google Chrome before 20.0.1132.43 does no
The image-codec implementation in the PDF functionality in Google Chrome before 20.0.1132.43 does not initialize an unspecified pointer, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2011-2801P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2801 [MEDIUM] CWE-416 CVE-2011-2801: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the frame loader.
nvd
CVE-2011-2789P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2789 [MEDIUM] CWE-416 CVE-2011-2789: Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to instantiation of the Pepper plug-in.
nvd
CVE-2012-2855P4MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2855 [MEDIUM] CWE-399 CVE-2012-2855: Use-after-free vulnerability in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS
Use-after-free vulnerability in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2012-2852P4MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2852 [MEDIUM] CWE-399 CVE-2012-2852: The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.11
The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly handle object linkage, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2015-6780P4MEDIUMCVSS 6.8≤ 46.0.2490.862015-12-06
CVE-2015-6780 [MEDIUM] CVE-2015-6780: Use-after-free vulnerability in the Infobars implementation in Google Chrome before 47.0.2526.73 all
Use-after-free vulnerability in the Infobars implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site, related to browser/ui/views/website_settings/website_settings_popup_view.cc.
nvd
CVE-2013-0884P4MEDIUMCVSS 6.8fixed in 25.0.1364.97fixed in 25.0.1364.992013-02-23
CVE-2013-0884 [MEDIUM] CVE-2013-0884: Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does no
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly load Native Client (aka NaCl) code, which has unspecified impact and attack vectors.
nvd