Google Chrome vulnerabilities
5,831 known vulnerabilities affecting google/chrome.
Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2
Vulnerabilities
Page 244 of 292
CVE-2026-17998P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17998 [MEDIUM] CWE-451 CVE-2026-17998: Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who
Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2026-17739P4MEDIUMCVSS 4.2fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17739 [MEDIUM] CWE-79 CVE-2026-17739: Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an att
Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2011-1814P4MEDIUMCVSS 5.8fixed in 12.0.742.912011-06-09
CVE-2011-1814 [MEDIUM] CWE-824 CVE-2011-1814: Google Chrome before 12.0.742.91 attempts to read data from an uninitialized pointer, which allows r
Google Chrome before 12.0.742.91 attempts to read data from an uninitialized pointer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2019-5765P4MEDIUMCVSS 5.5fixed in 72.0.3626.81≥ unspecified, < 72.0.3626.812019-02-19
CVE-2019-5765 [MEDIUM] CWE-312 CVE-2019-5765: An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allow
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
nvd
CVE-2013-2875P4MEDIUMCVSS 5.0≤ 28.0.1500.70v28.0.1500.0+61 more2013-07-10
CVE-2013-2875 [MEDIUM] CWE-119 CVE-2013-2875: core/rendering/svg/SVGInlineTextBox.cpp in the SVG implementation in Blink, as used in Google Chrome
core/rendering/svg/SVGInlineTextBox.cpp in the SVG implementation in Blink, as used in Google Chrome before 28.0.1500.71, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2011-3908P4MEDIUMCVSS 5.0fixed in 16.0.912.632011-12-13
CVE-2011-3908 [MEDIUM] CWE-125 CVE-2011-3908: Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attacker
Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2014-7909P4MEDIUMCVSS 5.0≤ 39.0.2171.452014-11-19
CVE-2014-7909 [MEDIUM] CWE-189 CVE-2014-7909: effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash
effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow remote attackers to cause a denial of service by rendering crafted data.
nvd
CVE-2011-1192P4MEDIUMCVSS 5.0fixed in 10.0.648.1272011-03-11
CVE-2011-1192 [MEDIUM] CWE-125 CVE-2011-1192: Google Chrome before 10.0.648.127 on Linux does not properly handle Unicode ranges, which allows rem
Google Chrome before 10.0.648.127 on Linux does not properly handle Unicode ranges, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2015-1246P4MEDIUMCVSS 5.0≤ 42.0.2311.602015-04-19
CVE-2015-1246 [MEDIUM] CWE-119 CVE-2015-1246: Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of se
Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2019-5804P4MEDIUMCVSS 5.5fixed in 73.0.3683.75vprior to 73.0.3683.752019-05-23
CVE-2019-5804 [MEDIUM] CWE-88 CVE-2019-5804: Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local a
Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local attacker to perform domain spoofing via a crafted domain name.
nvd
CVE-2016-5186P4MEDIUMCVSS 5.3≤ 53.0.2785.1432016-12-18
CVE-2016-5186 [MEDIUM] CWE-125 CVE-2016-5186: Devtools in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Androi
Devtools in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled objects after a tab crash, which allowed a remote attacker to perform an out of bounds memory read via crafted PDF files.
nvd
CVE-2013-2917P4MEDIUMCVSS 5.0≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2917 [MEDIUM] CWE-119 CVE-2013-2917: The ReverbConvolverStage::ReverbConvolverStage function in core/platform/audio/ReverbConvolverStage.
The ReverbConvolverStage::ReverbConvolverStage function in core/platform/audio/ReverbConvolverStage.cpp in the Web Audio implementation in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the impulseResponse array.
nvd
CVE-2013-2920P4MEDIUMCVSS 5.0≤ 30.0.1599.65v30.0.1599.0+57 more2013-10-02
CVE-2013-2920 [MEDIUM] CWE-119 CVE-2013-2920: The DoResolveRelativeHost function in url/url_canon_relative.cc in Google Chrome before 30.0.1599.66
The DoResolveRelativeHost function in url/url_canon_relative.cc in Google Chrome before 30.0.1599.66 allows remote attackers to cause a denial of service (out-of-bounds read) via a relative URL containing a hostname, as demonstrated by a protocol-relative URL beginning with a //www.google.com/ substring.
nvd
CVE-2014-1746P4MEDIUMCVSS 5.0≤ 35.0.1916.113v35.0.1916.0+78 more2014-05-21
CVE-2014-1746 [MEDIUM] CWE-119 CVE-2014-1746: The InMemoryUrlProtocol::Read function in media/filters/in_memory_url_protocol.cc in Google Chrome b
The InMemoryUrlProtocol::Read function in media/filters/in_memory_url_protocol.cc in Google Chrome before 35.0.1916.114 relies on an insufficiently large integer data type, which allows remote attackers to cause a denial of service (out-of-bounds read) via vectors that trigger use of a large buffer.
nvd
CVE-2011-3088P4MEDIUMCVSS 5.0≤ 19.0.1084.452012-05-16
CVE-2011-3088 [MEDIUM] CWE-119 CVE-2011-3088: Google Chrome before 19.0.1084.46 does not properly draw hairlines, which allows remote attackers to
Google Chrome before 19.0.1084.46 does not properly draw hairlines, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2014-3198P4MEDIUMCVSS 5.0≤ 38.0.2125.72014-10-08
CVE-2014-3198 [MEDIUM] CWE-119 CVE-2014-3198: The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome
The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
nvd
CVE-2012-2815P4MEDIUMCVSS 5.0≤ 20.0.1132.42v20.0.1132.0+41 more2012-06-27
CVE-2012-2815 [MEDIUM] CWE-200 CVE-2012-2815: Google Chrome before 20.0.1132.43 allows remote attackers to obtain potentially sensitive informatio
Google Chrome before 20.0.1132.43 allows remote attackers to obtain potentially sensitive information from a fragment identifier by leveraging access to an IFRAME element associated with a different domain.
nvd
CVE-2015-1240P4MEDIUMCVSS 5.0≤ 42.0.2311.602015-04-19
CVE-2015-1240 [MEDIUM] CWE-119 CVE-2015-1240: gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311
gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers a state inconsistency.
nvd
CVE-2010-4033P4MEDIUMCVSS 5.0≤ 7.0.517.40v6.0.454.0+177 more2010-10-21
CVE-2010-4033 [MEDIUM] CVE-2010-4033: Google Chrome before 7.0.517.41 does not properly implement the autofill and autocomplete functional
Google Chrome before 7.0.517.41 does not properly implement the autofill and autocomplete functionality, which allows remote attackers to conduct "profile spamming" attacks via unspecified vectors.
nvd
CVE-2011-4692P4MEDIUMCVSS 5.0≤ 152011-12-07
CVE-2011-4692 [MEDIUM] CWE-264 CVE-2011-4692: WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent
WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the browser cache via crafted JavaScript code, as demonstrated by visipisi.
nvd