cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 234 of 292
CVE-2011-3887P4MEDIUMCVSS 5.0fixed in 15.0.874.1022011-10-25
CVE-2011-3887 [MEDIUM] CWE-565 CVE-2011-3887: Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote att Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
nvd
CVE-2026-17973P4MEDIUMCVSS 5.5fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17973 [MEDIUM] CWE-200 CVE-2026-17973: Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2013-2908P4MEDIUMCVSS 5.0≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2908 [MEDIUM] CVE-2013-2908: Google Chrome before 30.0.1599.66 uses incorrect function calls to determine the values of Navigatio Google Chrome before 30.0.1599.66 uses incorrect function calls to determine the values of NavigationEntry objects, which allows remote attackers to spoof the address bar via vectors involving a response with a 204 (aka No Content) status code.
nvd
CVE-2026-8538P4MEDIUMCVSS 5.3fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8538 [MEDIUM] CWE-20 CVE-2026-8538: Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform a denial of service via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2010-4482P4MEDIUMCVSS 5.0≤ 8.0.552.2142010-12-07
CVE-2010-4482 [MEDIUM] CVE-2010-4482: Unspecified vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to bypass the Unspecified vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to bypass the pop-up blocker via unknown vectors.
nvd
CVE-2011-1304P4MEDIUMCVSS 5.0fixed in 11.0.696.572011-05-03
CVE-2011-1304 [MEDIUM] CVE-2011-1304: Unspecified vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to bypass the Unspecified vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to bypass the pop-up blocker via vectors related to plug-ins.
nvd
CVE-2026-11276P4MEDIUMCVSS 5.1fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11276 [MEDIUM] CWE-269 CVE-2026-11276: Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discretionary access control via malicious network traffic. (Chromium security severity: Low)
nvd
CVE-2011-3888P4MEDIUMCVSS 6.8fixed in 15.0.874.1022011-10-25
CVE-2011-3888 [MEDIUM] CWE-416 CVE-2011-3888: Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attack Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to editing operations in conjunction with an unknown plug-in.
nvd
CVE-2011-1204P4MEDIUMCVSS 6.8fixed in 10.0.648.1272011-03-11
CVE-2011-1204 [MEDIUM] CWE-20 CVE-2011-1204: Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers Google Chrome before 10.0.648.127 does not properly handle attributes, which allows remote attackers to cause a denial of service (DOM tree corruption) or possibly have unspecified other impact via a crafted document.
nvd
CVE-2011-2359P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2359 [MEDIUM] CWE-20 CVE-2011-2359: Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows Google Chrome before 13.0.782.107 does not properly track line boxes during rendering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-3958P4MEDIUMCVSS 6.8fixed in 17.0.963.462012-02-09
CVE-2011-3958 [MEDIUM] CWE-416 CVE-2011-3958: Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a c Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a column span, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2011-2348P4MEDIUMCVSS 6.8fixed in 12.0.742.1122011-06-29
CVE-2011-2348 [MEDIUM] CWE-119 CVE-2011-2348: Google V8, as used in Google Chrome before 12.0.742.112, performs an incorrect bounds check, which a Google V8, as used in Google Chrome before 12.0.742.112, performs an incorrect bounds check, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2015-6786P4MEDIUMCVSS 4.3≤ 46.0.2490.862015-12-06
CVE-2015-6786 [MEDIUM] CWE-264 CVE-2015-6786: The CSPSourceList::matches function in WebKit/Source/core/frame/csp/CSPSourceList.cpp in the Content The CSPSourceList::matches function in WebKit/Source/core/frame/csp/CSPSourceList.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts a blob:, data:, or filesystem: URL as a match for a * pattern, which allows remote attackers to bypass intended scheme restrictions in opportunistic circumstances by leve
nvd
CVE-2011-1813P4MEDIUMCVSS 6.8fixed in 12.0.742.912011-06-09
CVE-2011-1813 [MEDIUM] CWE-20 CVE-2011-1813: Google Chrome before 12.0.742.91 does not properly implement the framework for extensions, which all Google Chrome before 12.0.742.91 does not properly implement the framework for extensions, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2012-5136P4MEDIUMCVSS 6.8≤ 23.0.1271.89v23.0.1271.0+60 more2012-11-28
CVE-2012-5136 [MEDIUM] CWE-20 CVE-2012-5136: Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INPUT element, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted HTML document.
nvd
CVE-2011-2342P4MEDIUMCVSS 4.3fixed in 12.0.742.912011-06-09
CVE-2011-2342 [MEDIUM] CWE-79 CVE-2011-2342: The DOM implementation in Google Chrome before 12.0.742.91 allows remote attackers to bypass the Sam The DOM implementation in Google Chrome before 12.0.742.91 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
nvd
CVE-2011-2803P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2803 [MEDIUM] CWE-125 CVE-2011-2803: Google Chrome before 13.0.782.107 does not properly handle Skia paths, which allows remote attackers Google Chrome before 13.0.782.107 does not properly handle Skia paths, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-2791P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2791 [MEDIUM] CWE-787 CVE-2011-2791: The International Components for Unicode (ICU) functionality in Google Chrome before 13.0.782.107 al The International Components for Unicode (ICU) functionality in Google Chrome before 13.0.782.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.
nvd
CVE-2011-2794P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2794 [MEDIUM] CWE-125 CVE-2011-2794: Google Chrome before 13.0.782.107 does not properly perform text iteration, which allows remote atta Google Chrome before 13.0.782.107 does not properly perform text iteration, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-2350P4MEDIUMCVSS 6.8fixed in 12.0.742.1122011-06-29
CVE-2011-2350 [MEDIUM] CVE-2011-2350: The HTML parser in Google Chrome before 12.0.742.112 does not properly address "lifetime and re-entr The HTML parser in Google Chrome before 12.0.742.112 does not properly address "lifetime and re-entrancy issues," which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
Google Chrome vulnerabilities | cvebase