Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 238 of 292
CVE-2011-1447P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1447 [MEDIUM] CWE-20 CVE-2011-1447: Google Chrome before 11.0.696.57 does not properly handle drop-down lists, which allows remote attac
Google Chrome before 11.0.696.57 does not properly handle drop-down lists, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
nvd
CVE-2011-1443P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1443 [MEDIUM] CWE-20 CVE-2011-1443: Google Chrome before 11.0.696.57 does not properly implement layering, which allows remote attackers
Google Chrome before 11.0.696.57 does not properly implement layering, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."
nvd
CVE-2011-3015P4MEDIUMCVSS 6.8fixed in 17.0.963.562012-02-16
CVE-2011-3015 [MEDIUM] CWE-190 CVE-2011-3015: Multiple integer overflows in the PDF codecs in Google Chrome before 17.0.963.56 allow remote attack
Multiple integer overflows in the PDF codecs in Google Chrome before 17.0.963.56 allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2009-2416P4MEDIUMCVSS 6.5fixed in 2.0.172.432009-08-11
CVE-2009-2416 [MEDIUM] CWE-416 CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and l
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2011-1442P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1442 [MEDIUM] CWE-20 CVE-2011-1442: Google Chrome before 11.0.696.57 does not properly handle mutation events, which allows remote attac
Google Chrome before 11.0.696.57 does not properly handle mutation events, which allows remote attackers to cause a denial of service (node tree corruption) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2026-11249P4MEDIUMCVSS 4.7fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-05
CVE-2026-11249 [MEDIUM] CWE-416 CVE-2026-11249: Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had
Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-13992P4MEDIUMCVSS 4.7fixed in 139.0.7258.66≥ 139.0.7258.66, < 139.0.7258.662025-12-03
CVE-2025-13992 [MEDIUM] CWE-1300 CVE-2025-13992: Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 a
Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11233P4MEDIUMCVSS 4.7fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11233 [MEDIUM] CWE-20 CVE-2026-11233: Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a re
Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-13034P4MEDIUMCVSS 4.7fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13034 [MEDIUM] CWE-346 CVE-2026-13034: Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2011-3878P4MEDIUMCVSS 6.8fixed in 15.0.874.1022011-10-25
CVE-2011-3878 [MEDIUM] CWE-362 CVE-2011-3878: Race condition in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of ser
Race condition in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to worker process initialization.
nvd
CVE-2026-17706P4MEDIUMCVSS 4.3≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17706 [MEDIUM] CWE-20 CVE-2026-17706: Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17700P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17700 [MEDIUM] CWE-20 CVE-2026-17700: Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 allowed
Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-12433P4MEDIUMCVSS 4.3fixed in 142.0.7444.59≥ 142.0.7444.59, < 142.0.7444.592025-11-10
CVE-2025-12433 [MEDIUM] CVE-2025-12433: Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17794P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17794 [MEDIUM] CWE-20 CVE-2026-17794: Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922
Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17976P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17976 [MEDIUM] CWE-284 CVE-2026-17976: Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an att
Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted domain name. (Chromium security severity: Low)
nvd
CVE-2026-7912P4MEDIUMCVSS 4.2fixed in 148.0.7778.96≥ 148.0.7778.96, < 148.0.7778.962026-05-06
CVE-2026-7912 [MEDIUM] CWE-472 CVE-2026-7912: Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker
Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2013-2879P4MEDIUMCVSS 5.8≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2879 [MEDIUM] CWE-200 CVE-2013-2879: Google Chrome before 28.0.1500.71 does not properly determine the circumstances in which a renderer
Google Chrome before 28.0.1500.71 does not properly determine the circumstances in which a renderer process can be considered a trusted process for sign-in and subsequent sync operations, which makes it easier for remote attackers to conduct phishing attacks via a crafted web site.
nvd
CVE-2011-3964P4MEDIUMCVSS 5.8fixed in 17.0.963.462012-02-09
CVE-2011-3964 [MEDIUM] CWE-20 CVE-2011-3964: Google Chrome before 17.0.963.46 does not properly implement the drag-and-drop feature, which makes
Google Chrome before 17.0.963.46 does not properly implement the drag-and-drop feature, which makes it easier for remote attackers to spoof the URL bar via unspecified vectors.
nvd
CVE-2020-15989P4MEDIUMCVSS 5.5fixed in 86.0.4240.75≥ unspecified, < 86.0.4240.752020-11-03
CVE-2020-15989 [MEDIUM] CWE-908 CVE-2020-15989: Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obt
Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
nvd
CVE-2018-18358P4MEDIUMCVSS 5.7fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18358 [MEDIUM] CWE-20 CVE-2018-18358: Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an
Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
nvd