cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 237 of 292
CVE-2014-3174P4MEDIUMCVSS 5.0≤ 37.0.2062.93v37.0.2062.0+80 more2014-08-27
CVE-2014-3174 [MEDIUM] CWE-119 CVE-2014-3174: modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly consider concurrent threads during attempts to update biquad filter coefficients, which allows remote attackers to cause a denial of service (read of uninitialized memory) via crafted API calls.
nvd
CVE-2015-1296P4MEDIUMCVSS 5.0≤ 44.0.24032015-09-03
CVE-2015-1296 [MEDIUM] CWE-254 CVE-2015-1296: The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0 The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by placing one of these characters at the end of a URL, as demonstrated by the omnibox in localizations fo
nvd
CVE-2026-13929P4MEDIUMCVSS 5.5fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13929 [MEDIUM] CWE-20 CVE-2026-13929: Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 150.0.7871.47 allow Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2025-12439P4MEDIUMCVSS 5.5fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12439 [MEDIUM] CWE-326 CVE-2025-12439: Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444 Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444.59 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2014-7899P4MEDIUMCVSS 5.0≤ 38.0.2125.72014-11-19
CVE-2014-7899 [MEDIUM] CWE-20 CVE-2014-7899: Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blo Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followed by the original URI scheme and a long username string.
nvd
CVE-2014-3195P4MEDIUMCVSS 5.0≤ 38.0.2125.72014-10-08
CVE-2014-3195 [MEDIUM] CWE-399 CVE-2014-3195: Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-me Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as allocations of uninitialized memory and does not properly concatenate arrays of double-precision floating-point numbers, which allows remote attackers to obtain sensitive information via crafted JavaScript code, related to the PagedS
nvd
CVE-2013-2868P4MEDIUMCVSS 5.0≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2868 [MEDIUM] CVE-2013-2868: common/extensions/sync_helper.cc in Google Chrome before 28.0.1500.71 proceeds with sync operations common/extensions/sync_helper.cc in Google Chrome before 28.0.1500.71 proceeds with sync operations for NPAPI extensions without checking for a certain plugin permission setting, which might allow remote attackers to trigger unwanted extension changes via unspecified vectors.
nvd
CVE-2011-1801P4MEDIUMCVSS 5.0fixed in 11.0.696.712011-05-26
CVE-2011-1801 [MEDIUM] CVE-2011-1801: Unspecified vulnerability in Google Chrome before 11.0.696.71 allows remote attackers to bypass the Unspecified vulnerability in Google Chrome before 11.0.696.71 allows remote attackers to bypass the pop-up blocker via unknown vectors.
nvd
CVE-2014-7939P4MEDIUMCVSS 4.3≤ 40.0.2214.852015-01-22
CVE-2014-7939 [MEDIUM] CWE-264 CVE-2014-7939: Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote att Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.
nvd
CVE-2012-5155P4MEDIUMCVSS 5.0≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2012-5155 [MEDIUM] CWE-264 CVE-2012-5155: Google Chrome before 24.0.1312.52 on Mac OS X does not use an appropriate sandboxing approach for wo Google Chrome before 24.0.1312.52 on Mac OS X does not use an appropriate sandboxing approach for worker processes, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2011-2855P4MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2855 [MEDIUM] CWE-74 CVE-2011-2855: Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequen Google Chrome before 14.0.835.163 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale node."
nvd
CVE-2020-6441P4MEDIUMCVSS 4.3fixed in 81.0.4044.92≥ unspecified, < 81.0.4044.922020-04-13
CVE-2020-6441 [MEDIUM] CWE-276 CVE-2020-6441: Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote a Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.
nvd
CVE-2015-6785P4MEDIUMCVSS 4.3≤ 46.0.2490.862015-12-06
CVE-2015-6785 [MEDIUM] CWE-264 CVE-2015-6785: The CSPSource::hostMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Sec The CSPSource::hostMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts an x.y hostname as a match for a *.x.y pattern, which might allow remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a polic
nvd
CVE-2011-1200P4MEDIUMCVSS 6.8fixed in 10.0.648.1272011-03-11
CVE-2011-1200 [MEDIUM] CWE-704 CVE-2011-1200: Google Chrome before 10.0.648.127 does not properly perform a cast of an unspecified variable during Google Chrome before 10.0.648.127 does not properly perform a cast of an unspecified variable during text rendering, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.
nvd
CVE-2011-2875P4MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2875 [MEDIUM] CWE-843 CVE-2011-2875: Google V8, as used in Google Chrome before 14.0.835.163, does not properly perform object sealing, w Google V8, as used in Google Chrome before 14.0.835.163, does not properly perform object sealing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
nvd
CVE-2015-1248P4MEDIUMCVSS 4.3≤ 40.0.2214.852015-04-19
CVE-2015-1248 [MEDIUM] CWE-264 CVE-2015-1248: The FileSystem API in Google Chrome before 40.0.2214.91 allows remote attackers to bypass the SafeBr The FileSystem API in Google Chrome before 40.0.2214.91 allows remote attackers to bypass the SafeBrowsing for Executable Files protection mechanism by creating a .exe file in a temporary filesystem and then referencing this file with a filesystem:http: URL.
nvd
CVE-2024-6995P4MEDIUMCVSS 4.7fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-6995 [MEDIUM] CWE-358 CVE-2024-6995: Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowe Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-3884P4MEDIUMCVSS 6.8fixed in 15.0.874.1022011-10-25
CVE-2011-3884 [MEDIUM] CWE-20 CVE-2011-3884: Google Chrome before 15.0.874.102 does not properly address timing issues during DOM traversal, whic Google Chrome before 15.0.874.102 does not properly address timing issues during DOM traversal, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
nvd
CVE-2011-2852P4MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2852 [MEDIUM] CWE-193 CVE-2011-2852: Off-by-one error in Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers Off-by-one error in Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-2881P4MEDIUMCVSS 6.8fixed in 14.0.835.2022011-10-04
CVE-2011-2881 [MEDIUM] CWE-119 CVE-2011-2881: Google Chrome before 14.0.835.202 does not properly handle Google V8 hidden objects, which allows re Google Chrome before 14.0.835.202 does not properly handle Google V8 hidden objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.
nvd
Google Chrome vulnerabilities | cvebase