Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 241 of 292
CVE-2013-2874P4MEDIUMCVSS 4.3≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2874 [MEDIUM] CWE-264 CVE-2013-2874: Google Chrome before 28.0.1500.71 on Windows, when an Nvidia GPU is used, allows remote attackers to
Google Chrome before 28.0.1500.71 on Windows, when an Nvidia GPU is used, allows remote attackers to bypass intended restrictions on access to screen data via vectors involving IPC transmission of GL textures.
nvd
CVE-2011-1456P4MEDIUMCVSS 6.8fixed in 11.0.696.572011-05-03
CVE-2011-1456 [MEDIUM] CWE-20 CVE-2011-1456: Google Chrome before 11.0.696.57 does not properly handle PDF forms, which allows remote attackers t
Google Chrome before 11.0.696.57 does not properly handle PDF forms, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."
nvd
CVE-2011-2802P4MEDIUMCVSS 6.8fixed in 13.0.782.1072011-08-03
CVE-2011-2802 [MEDIUM] CWE-20 CVE-2011-2802: Google V8, as used in Google Chrome before 13.0.782.107, does not properly perform const lookups, wh
Google V8, as used in Google Chrome before 13.0.782.107, does not properly perform const lookups, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2011-1799P4MEDIUMCVSS 6.8fixed in 11.0.696.682011-05-16
CVE-2011-1799 [MEDIUM] CWE-704 CVE-2011-1799: Google Chrome before 11.0.696.68 does not properly perform casts of variables during interaction wit
Google Chrome before 11.0.696.68 does not properly perform casts of variables during interaction with the WebKit engine, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2019-5839P4MEDIUMCVSS 4.3fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5839 [MEDIUM] CWE-20 CVE-2019-5839: Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote atta
Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.
nvd
CVE-2023-7013P4MEDIUMCVSS 4.7fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052024-07-16
CVE-2023-7013 [MEDIUM] CWE-1021 CVE-2023-7013: Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remot
Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-2879P4MEDIUMCVSS 6.8fixed in 14.0.835.2022011-10-04
CVE-2011-2879 [MEDIUM] CVE-2011-2879: Google Chrome before 14.0.835.202 does not properly consider object lifetimes and thread safety duri
Google Chrome before 14.0.835.202 does not properly consider object lifetimes and thread safety during the handling of audio nodes, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-2859P4MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2859 [MEDIUM] CWE-276 CVE-2011-2859: Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspec
Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspecified impact and attack vectors.
nvd
CVE-2026-8565P4MEDIUMCVSS 4.7fixed in 148.0.7778.168≥ 148.0.7778.168, < 148.0.7778.1682026-05-14
CVE-2026-8565 [MEDIUM] CWE-451 CVE-2026-8565: Inappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an
Inappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2012-2860P4MEDIUMCVSS 6.8≤ 21.0.1180.56v21.0.1180.0+25 more2012-08-06
CVE-2012-2860 [MEDIUM] CVE-2012-2860: The date-picker implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and befor
The date-picker implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.
nvd
CVE-2011-2874P4MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2874 [MEDIUM] CWE-295 CVE-2011-2874: Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certi
Google Chrome before 14.0.835.163 does not perform an expected pin operation for a self-signed certificate during a session, which has unspecified impact and remote attack vectors.
nvd
CVE-2024-7005P4MEDIUMCVSS 4.3fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-7005 [MEDIUM] CWE-20 CVE-2024-7005: Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low)
nvd
CVE-2024-7004P4MEDIUMCVSS 4.3fixed in 127.0.6533.72≥ 127.0.6533.72, < 127.0.6533.722024-08-06
CVE-2024-7004 [MEDIUM] CWE-20 CVE-2024-7004: Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low)
nvd
CVE-2026-17808P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17808 [MEDIUM] CWE-457 CVE-2026-17808: Uninitialized Use in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attac
Uninitialized Use in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17859P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17859 [MEDIUM] CWE-1300 CVE-2026-17859: Inappropriate implementation in Favicons in Google Chrome prior to 151.0.7922.72 allowed a remote at
Inappropriate implementation in Favicons in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17934P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17934 [MEDIUM] CWE-20 CVE-2026-17934: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allow
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14058P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14058 [MEDIUM] CWE-693 CVE-2026-14058: Insufficient policy enforcement in Parser in Google Chrome prior to 150.0.7871.47 allowed a remote a
Insufficient policy enforcement in Parser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-13865P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-13865 [MEDIUM] CWE-20 CVE-2026-13865: Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 all
Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17938P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17938 [MEDIUM] CWE-451 CVE-2026-17938: Inappropriate implementation in FullScreen in Google Chrome on Android prior to 151.0.7922.72 allowe
Inappropriate implementation in FullScreen in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17941P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17941 [MEDIUM] CWE-451 CVE-2026-17941: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
nvd