Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 235 of 292
CVE-2011-2347P4MEDIUMCVSS 6.8fixed in 12.0.742.1122011-06-29
CVE-2011-2347 [MEDIUM] CWE-119 CVE-2011-2347: Google Chrome before 12.0.742.112 does not properly handle Cascading Style Sheets (CSS) token sequen
Google Chrome before 12.0.742.112 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2012-2895P4MEDIUMCVSS 6.8≤ 22.0.1229.78v22.0.1229.0+51 more2012-09-26
CVE-2012-2895 [MEDIUM] CWE-119 CVE-2012-2895: The PDF functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial
The PDF functionality in Google Chrome before 22.0.1229.79 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-of-bounds write operations.
nvd
CVE-2026-14154P4MEDIUMCVSS 4.8fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14154 [MEDIUM] CWE-451 CVE-2026-14154: Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2013-0926P4MEDIUMCVSS 6.8≤ 26.0.1410.42v26.0.1410.0+40 more2013-03-28
CVE-2013-0926 [MEDIUM] CWE-20 CVE-2013-0926: Google Chrome before 26.0.1410.43 does not properly handle active content in an EMBED element during
Google Chrome before 26.0.1410.43 does not properly handle active content in an EMBED element during a copy-and-paste operation, which allows user-assisted remote attackers to have an unspecified impact via a crafted web site.
nvd
CVE-2012-2851P4MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2851 [MEDIUM] CWE-189 CVE-2012-2851: Multiple integer overflows in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X
Multiple integer overflows in the PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2011-1454P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1454 [MEDIUM] CWE-416 CVE-2011-1454: Use-after-free vulnerability in the DOM id handling functionality in Google Chrome before 11.0.696.5
Use-after-free vulnerability in the DOM id handling functionality in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document.
nvd
CVE-2011-1437P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1437 [MEDIUM] CWE-190 CVE-2011-1437: Multiple integer overflows in Google Chrome before 11.0.696.57 allow remote attackers to cause a den
Multiple integer overflows in Google Chrome before 11.0.696.57 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float rendering.
nvd
CVE-2015-1298P4MEDIUMCVSS 4.3≤ 44.0.24032015-09-03
CVE-2015-1298 [MEDIUM] CWE-254 CVE-2015-1298: The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_ap
The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-assisted remote attackers to trigger access to an arbitrary URL via a crafted extension that is uninsta
nvd
CVE-2011-2880P4MEDIUMCVSS 6.8fixed in 14.0.835.2022011-10-04
CVE-2011-2880 [MEDIUM] CWE-416 CVE-2011-2880: Use-after-free vulnerability in Google Chrome before 14.0.835.202 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 14.0.835.202 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the Google V8 bindings.
nvd
CVE-2011-1445P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1445 [MEDIUM] CWE-125 CVE-2011-1445: Google Chrome before 11.0.696.57 does not properly handle SVG documents, which allows remote attacke
Google Chrome before 11.0.696.57 does not properly handle SVG documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-2876P4MEDIUMCVSS 6.8fixed in 14.0.835.2022011-10-04
CVE-2011-2876 [MEDIUM] CWE-416 CVE-2011-2876: Use-after-free vulnerability in Google Chrome before 14.0.835.202 allows remote attackers to cause a
Use-after-free vulnerability in Google Chrome before 14.0.835.202 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a text line box.
nvd
CVE-2012-2819P4MEDIUMCVSS 6.8≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2819 [MEDIUM] CWE-20 CVE-2012-2819: The texSubImage2D implementation in the WebGL subsystem in Google Chrome before 20.0.1132.43 does no
The texSubImage2D implementation in the WebGL subsystem in Google Chrome before 20.0.1132.43 does not properly handle uploads to floating-point textures, which allows remote attackers to cause a denial of service (assertion failure and application crash) or possibly have unspecified other impact via a crafted web page, as demonstrated by certain WebGL
nvd
CVE-2026-13812P4MEDIUMCVSS 4.7fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13812 [MEDIUM] CWE-20 CVE-2026-13812: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2011-3023P4MEDIUMCVSS 6.8fixed in 17.0.963.562012-02-16
CVE-2011-3023 [MEDIUM] CWE-416 CVE-2011-3023: Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows user-assisted remote attacke
Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to drag-and-drop operations.
nvd
CVE-2012-5151P4MEDIUMCVSS 6.8≤ 24.0.1312.51v24.0.1272.0+110 more2013-01-15
CVE-2012-5151 [MEDIUM] CWE-189 CVE-2012-5151: Integer overflow in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of s
Integer overflow in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code in a PDF document.
nvd
CVE-2011-1439P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1439 [MEDIUM] CVE-2011-1439: Google Chrome before 11.0.696.57 on Linux does not properly isolate renderer processes, which has un
Google Chrome before 11.0.696.57 on Linux does not properly isolate renderer processes, which has unspecified impact and remote attack vectors.
nvd
CVE-2011-3020P4MEDIUMCVSS 6.8fixed in 17.0.963.562012-02-16
CVE-2011-3020 [MEDIUM] CVE-2011-3020: Unspecified vulnerability in the Native Client validator implementation in Google Chrome before 17.0
Unspecified vulnerability in the Native Client validator implementation in Google Chrome before 17.0.963.56 has unknown impact and remote attack vectors.
nvd
CVE-2011-3876P4MEDIUMCVSS 6.8fixed in 15.0.874.1022011-10-25
CVE-2011-3876 [MEDIUM] CVE-2011-3876: Google Chrome before 15.0.874.102 does not properly handle downloading files that have whitespace ch
Google Chrome before 15.0.874.102 does not properly handle downloading files that have whitespace characters at the end of a filename, which has unspecified impact and user-assisted remote attack vectors.
nvd
CVE-2012-2853P4MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2853 [MEDIUM] CVE-2012-2853: The webRequest API in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.
The webRequest API in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly interact with the Chrome Web Store, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2026-17849P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17849 [MEDIUM] CWE-451 CVE-2026-17849: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via malicious network traffic. (Chromium security severity: Medium)
nvd