cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 246 of 292
CVE-2020-6536P4MEDIUMCVSS 4.3fixed in 84.0.4147.89≥ unspecified, < 84.0.4147.892020-07-22
CVE-2020-6536 [MEDIUM] CVE-2020-6536: Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who h Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.
nvd
CVE-2014-1726P4MEDIUMCVSS 4.3≤ 34.0.1847.1152014-04-09
CVE-2014-1726 [MEDIUM] CVE-2014-1726: The drag implementation in Google Chrome before 34.0.1847.116 allows user-assisted remote attackers The drag implementation in Google Chrome before 34.0.1847.116 allows user-assisted remote attackers to bypass the Same Origin Policy and forge local pathnames by leveraging renderer access.
nvd
CVE-2014-3803P4MEDIUMCVSS 4.3≤ 35.0.1916.113v35.0.1916.0+78 more2014-05-21
CVE-2014-3803 [MEDIUM] CWE-200 CVE-2014-3803: The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attac The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-webkit-speech attribute.
nvd
CVE-2013-2632P4MEDIUMCVSS 6.8≤ 27.0.1444.02013-03-21
CVE-2013-2632 [MEDIUM] CVE-2013-2632: Google V8 before 3.17.13, as used in Google Chrome before 27.0.1444.3, allows remote attackers to ca Google V8 before 3.17.13, as used in Google Chrome before 27.0.1444.3, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code, as demonstrated by the Bejeweled game.
nvd
CVE-2010-4037P4MEDIUMCVSS 4.3≤ 7.0.517.40v6.0.454.0+177 more2010-10-21
CVE-2010-4037 [MEDIUM] CVE-2010-4037: Unspecified vulnerability in Google Chrome before 7.0.517.41 allows remote attackers to bypass the p Unspecified vulnerability in Google Chrome before 7.0.517.41 allows remote attackers to bypass the pop-up blocker via unknown vectors.
nvd
CVE-2011-2782P4MEDIUMCVSS 4.3fixed in 13.0.782.1072011-08-03
CVE-2011-2782 [MEDIUM] CWE-276 CVE-2011-2782: The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enf The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.
nvd
CVE-2013-6636P4MEDIUMCVSS 4.3≤ 31.0.1650.62v31.0.1650.0+56 more2013-12-07
CVE-2013-6636 [MEDIUM] CWE-20 CVE-2013-6636: The FrameLoader::notifyIfInitialDocumentAccessed function in core/loader/FrameLoader.cpp in Blink, a The FrameLoader::notifyIfInitialDocumentAccessed function in core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 31.0.1650.63, makes an incorrect check for an empty document during presentation of a modal dialog, which allows remote attackers to spoof the address bar via vectors involving the document.write method.
nvd
CVE-2021-37971P4MEDIUMCVSS 4.3fixed in 94.0.4606.54≥ unspecified, < 94.0.4606.542021-10-08
CVE-2021-37971 [MEDIUM] CWE-1021 CVE-2021-37971: Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote atta Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2013-0836P4MEDIUMCVSS 6.8≤ 24.0.1312.51v24.0.1272.0+119 more2013-01-15
CVE-2013-0836 [MEDIUM] CWE-399 CVE-2013-0836: Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, does not properly implement Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, does not properly implement garbage collection, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2016-1625P4MEDIUMCVSS 4.3≤ 48.0.2564.1032016-02-14
CVE-2016-1625 [MEDIUM] CWE-264 CVE-2016-1625: The Chrome Instant feature in Google Chrome before 48.0.2564.109 does not ensure that a New Tab Page The Chrome Instant feature in Google Chrome before 48.0.2564.109 does not ensure that a New Tab Page (NTP) navigation target is on the most-visited or suggestions list, which allows remote attackers to bypass intended restrictions via unspecified vectors, related to instant_service.cc and search_tab_helper.cc.
nvd
CVE-2021-30532P4MEDIUMCVSS 4.3fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30532 [MEDIUM] CVE-2021-30532: Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 al Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2019-13757P4MEDIUMCVSS 4.3fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13757 [MEDIUM] CVE-2019-13757: Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2021-21186P4MEDIUMCVSS 4.3fixed in 89.0.4389.72≥ unspecified, < 89.0.4389.722021-03-09
CVE-2021-21186 [MEDIUM] CWE-863 CVE-2021-21186: Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who convinced the user to scan a QR code to bypass navigation restrictions via a crafted QR code.
nvd
CVE-2022-0112P4MEDIUMCVSS 4.3fixed in 97.0.4692.71≥ unspecified, < 97.0.4692.712022-02-12
CVE-2022-0112 [MEDIUM] CVE-2022-0112: Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to display missing URL or incorrect URL via a crafted URL.
nvd
CVE-2023-5850P4MEDIUMCVSS 4.3fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5850 [MEDIUM] CVE-2023-5850: Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacke Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
nvd
CVE-2017-15392P4MEDIUMCVSS 4.3fixed in 62.0.3202.622018-02-07
CVE-2017-15392 [MEDIUM] CWE-20 CVE-2017-15392: Insufficient data validation in V8 in Google Chrome prior to 62.0.3202.62 allowed an attacker who ca Insufficient data validation in V8 in Google Chrome prior to 62.0.3202.62 allowed an attacker who can write to the Windows Registry to potentially exploit heap corruption via a crafted Windows Registry entry, related to PlatformIntegration.
nvd
CVE-2023-2468P4MEDIUMCVSS 4.3fixed in 113.0.5672.63≥ 113.0.5672.63, < 113.0.5672.632023-05-03
CVE-2023-2468 [MEDIUM] CVE-2023-2468: Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a r Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-3845P4MEDIUMCVSS 4.3fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-04-17
CVE-2024-3845 [MEDIUM] CWE-358 CVE-2024-3845: Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote at Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4901P4MEDIUMCVSS 4.3fixed in 117.0.5938.62≥ 117.0.5938.62, < 117.0.5938.622023-09-12
CVE-2023-4901 [MEDIUM] CVE-2023-4901: Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote att Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4905P4MEDIUMCVSS 4.3fixed in 117.0.5938.62≥ 117.0.5938.62, < 117.0.5938.622023-09-12
CVE-2023-4905 [MEDIUM] CVE-2023-4905: Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote att Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase