Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 239 of 292
CVE-2011-3049P4MEDIUMCVSS 5.0fixed in 17.0.963.832012-03-23
CVE-2011-3049 [MEDIUM] CVE-2011-3049: Google Chrome before 17.0.963.83 does not properly restrict the extension web request API, which all
Google Chrome before 17.0.963.83 does not properly restrict the extension web request API, which allows remote attackers to cause a denial of service (disrupted system requests) via a crafted extension.
nvd
CVE-2015-1206P4MEDIUMCVSS 5.5≤ 41.0.2251.02017-10-06
CVE-2015-1206 [MEDIUM] CWE-119 CVE-2015-1206: Heap-based buffer overflow in Google Chrome before M40 allows remote attackers to cause a denial of
Heap-based buffer overflow in Google Chrome before M40 allows remote attackers to cause a denial of service (unpaged memory write and process crash) via a crafted MP4 file.
nvd
CVE-2016-1693P4MEDIUMCVSS 5.3≤ 50.0.2661.1022016-06-05
CVE-2016-1693 [MEDIUM] CWE-284 CVE-2016-1693: browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the H
browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chrome_cleanup_tool.exe (aka CCT) file via a man-in-the-middle attack on an HTTP session.
nvd
CVE-2021-37990P4MEDIUMCVSS 5.5fixed in 95.0.4638.54≥ unspecified, < 95.0.4638.542021-11-02
CVE-2021-37990 [MEDIUM] CVE-2021-37990: Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a
Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.
nvd
CVE-2014-7924P4MEDIUMCVSS 5.0≤ 40.0.2214.852015-01-22
CVE-2014-7924 [MEDIUM] CVE-2014-7924: Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 40.0.2214.91 al
Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering duplicate BLOB references, related to content/browser/indexed_db/indexed_db_callbacks.cc and content/browser/indexed_db/indexed_db_dispatcher_host.cc.
nvd
CVE-2011-3909P4MEDIUMCVSS 5.0fixed in 16.0.912.632011-12-13
CVE-2011-3909 [MEDIUM] CWE-119 CVE-2011-3909: The Cascading Style Sheets (CSS) implementation in Google Chrome before 16.0.912.63 on 64-bit platfo
The Cascading Style Sheets (CSS) implementation in Google Chrome before 16.0.912.63 on 64-bit platforms does not properly manage property arrays, which allows remote attackers to cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2018-6147P4MEDIUMCVSS 5.5fixed in 67.0.3396.62≥ unspecified, < 67.0.3396.622019-01-09
CVE-2018-6147 [MEDIUM] CWE-200 CVE-2018-6147: Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a
Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive information from process memory via a local process.
nvd
CVE-2014-3155P4MEDIUMCVSS 5.0≤ 35.0.1916.152v35.0.1916.0+102 more2014-06-11
CVE-2014-3155 [MEDIUM] CVE-2014-3155: net/spdy/spdy_write_queue.cc in the SPDY implementation in Google Chrome before 35.0.1916.153 allows
net/spdy/spdy_write_queue.cc in the SPDY implementation in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service (out-of-bounds read) by leveraging incorrect queue maintenance.
nvd
CVE-2017-5082P4MEDIUMCVSS 5.5fixed in 59.0.3071.922017-10-27
CVE-2017-5082 [MEDIUM] CWE-200 CVE-2017-5082: Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to
Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacker to take screen shots of credit card information via a crafted HTML page.
nvd
CVE-2024-3838P4MEDIUMCVSS 5.5fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-04-17
CVE-2024-3838 [MEDIUM] CWE-358 CVE-2024-3838: Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker
Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app to perform UI spoofing via a crafted app. (Chromium security severity: Medium)
nvd
CVE-2014-7943P4MEDIUMCVSS 5.0≤ 40.0.2214.852015-01-22
CVE-2014-7943 [MEDIUM] CWE-119 CVE-2014-7943: Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of ser
Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2018-20073P4MEDIUMCVSS 5.5fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-06-27
CVE-2018-20073 [MEDIUM] CWE-200 CVE-2018-20073: Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attac
Use of extended attributes in downloads in Google Chrome prior to 72.0.3626.81 allowed a local attacker to read download URLs via the filesystem.
nvd
CVE-2015-1244P4MEDIUMCVSS 5.0≤ 42.0.2311.602015-04-19
CVE-2015-1244 [MEDIUM] CWE-200 CVE-2015-1244: The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.
The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.
nvd
CVE-2011-1194P4MEDIUMCVSS 5.0fixed in 10.0.648.1272011-03-11
CVE-2011-1194 [MEDIUM] CVE-2011-1194: Multiple unspecified vulnerabilities in Google Chrome before 10.0.648.127 allow remote attackers to
Multiple unspecified vulnerabilities in Google Chrome before 10.0.648.127 allow remote attackers to bypass the pop-up blocker via unknown vectors.
nvd
CVE-2015-1261P4MEDIUMCVSS 5.0≤ 42.0.2311.1072015-05-20
CVE-2015-1261 [MEDIUM] CWE-20 CVE-2015-1261: android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.
android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.
nvd
CVE-2015-6759P4MEDIUMCVSS 5.0≤ 45.0.2454.1012015-10-15
CVE-2015-6759 [MEDIUM] CWE-200 CVE-2015-6759: The shouldTreatAsUniqueOrigin function in platform/weborigin/SecurityOrigin.cpp in Blink, as used in
The shouldTreatAsUniqueOrigin function in platform/weborigin/SecurityOrigin.cpp in Blink, as used in Google Chrome before 46.0.2490.71, does not ensure that the origin of a LocalStorage resource is considered unique, which allows remote attackers to obtain sensitive information via vectors involving a blob: URL.
nvd
CVE-2014-1725P4MEDIUMCVSS 5.0≤ 34.0.1847.1152014-04-09
CVE-2014-1725 [MEDIUM] CWE-20 CVE-2014-1725: The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used in Google Chrome before 3
The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used in Google Chrome before 34.0.1847.116, does not properly handle string data composed exclusively of whitespace characters, which allows remote attackers to cause a denial of service (out-of-bounds read) via a window.atob method call.
nvd
CVE-2014-3199P4MEDIUMCVSS 5.0≤ 38.0.2125.72014-10-08
CVE-2014-3199 [MEDIUM] CWE-399 CVE-2014-3199: The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used
The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 38.0.2125.101, has an erroneous fallback outcome for wrapper-selection failures, which allows remote attackers to cause a denial of service via vectors that trigger stopping a worker process that had been handling an Event object.
nvd
CVE-2014-9689P4MEDIUMCVSS 5.0≤ 40.0.2214.1152015-03-09
CVE-2014-9689 [MEDIUM] CWE-264 CVE-2014-9689: content/renderer/device_sensors/device_orientation_event_pump.cc in Google Chrome before 41.0.2272.7
content/renderer/device_sensors/device_orientation_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate gyroscope data, which makes it easier for remote attackers to obtain speech signals from a device's physical environment via a crafted web site that listens for ondeviceorientation events, a different vul
nvd
CVE-2011-1435P4MEDIUMCVSS 5.0fixed in 11.0.696.572011-05-03
CVE-2011-1435 [MEDIUM] CWE-276 CVE-2011-1435: Google Chrome before 11.0.696.57 does not properly implement the tabs permission for extensions, whi
Google Chrome before 11.0.696.57 does not properly implement the tabs permission for extensions, which allows remote attackers to read local files via a crafted extension.
nvd