Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82
Vulnerabilities
Page 24 of 292
CVE-2024-4558P3CRITICALCVSS 9.6fixed in 124.0.6367.155≥ 124.0.6367.155, < 124.0.6367.1552024-05-07
CVE-2024-4558 [CRITICAL] CWE-416 CVE-2024-4558: Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potent
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-2883P3HIGHCVSS 8.8fixed in 123.0.6312.86≥ 123.0.6312.86, < 123.0.6312.862024-03-26
CVE-2024-2883 [HIGH] CWE-416 CVE-2024-2883: Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potenti
Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2023-4428P3HIGHCVSS 8.1fixed in 116.0.5845.110≥ 116.0.5845.110, < 116.0.5845.1102023-08-23
CVE-2023-4428 [HIGH] CWE-125 CVE-2023-4428: Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacke
Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-1939P3HIGHCVSS 8.8fixed in 122.0.6261.94≥ 122.0.6261.94, < 122.0.6261.942024-02-29
CVE-2024-1939 [HIGH] CWE-843 CVE-2024-1939: Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentiall
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2025-5280P3HIGHCVSS 8.8fixed in 137.0.7151.55≥ 137.0.7151.55, < 137.0.7151.552025-05-27
CVE-2025-5280 [HIGH] CWE-787 CVE-2025-5280: Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to poten
Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17681P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17681 [CRITICAL] CWE-20 CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior t
Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13920P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13920 [CRITICAL] CWE-20 CVE-2026-13920: Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11021P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11021 [CRITICAL] CWE-20 CVE-2026-11021: Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53
Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-10971P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-10971 [CRITICAL] CWE-20 CVE-2026-10971: Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.78
Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13780P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13780 [CRITICAL] CWE-20 CVE-2026-13780: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-13781P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13781 [CRITICAL] CWE-20 CVE-2026-13781: Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a
Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-13883P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13883 [CRITICAL] CWE-843 CVE-2026-13883: Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potenti
Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17651P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17651 [CRITICAL] CWE-20 CVE-2026-17651: Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.7
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-13796P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13796 [CRITICAL] CWE-472 CVE-2026-13796: Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13797P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13797 [CRITICAL] CWE-20 CVE-2026-13797: Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.47 all
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-11047P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11047 [CRITICAL] CWE-20 CVE-2026-11047: Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a re
Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17676P3CRITICALCVSS 9.6≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17676 [CRITICAL] CWE-693 CVE-2026-17676: Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a r
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-13878P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13878 [CRITICAL] CWE-416 CVE-2026-13878: Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker
Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13859P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13859 [CRITICAL] CWE-693 CVE-2026-13859: Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attac
Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-13880P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13880 [CRITICAL] CWE-416 CVE-2026-13880: Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who h
Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd