cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 249 of 292
CVE-2026-17767P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17767 [MEDIUM] CWE-20 CVE-2026-17767: Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.792 Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17880P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17880 [MEDIUM] CWE-346 CVE-2026-17880: Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17879P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17879 [MEDIUM] CWE-346 CVE-2026-17879: Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-9911P4MEDIUMCVSS 4.3fixed in 148.0.7778.216≥ 148.0.7778.216, < 148.0.7778.2162026-05-28
CVE-2026-9911 [MEDIUM] CWE-472 CVE-2026-9911: Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perf Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-17662P4MEDIUMCVSS 4.3≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17662 [MEDIUM] CWE-346 CVE-2026-17662: Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14127P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14127 [MEDIUM] CWE-451 CVE-2026-14127: Inappropriate implementation in Printing in Google Chrome prior to 150.0.7871.47 allowed a remote at Inappropriate implementation in Printing in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14130P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14130 [MEDIUM] CWE-451 CVE-2026-14130: Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker t Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14141P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14141 [MEDIUM] CWE-451 CVE-2026-14141: Incorrect security UI in Document Picture-in-Picture in Google Chrome on Android prior to 150.0.7871 Incorrect security UI in Document Picture-in-Picture in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-17753P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17753 [MEDIUM] CWE-346 CVE-2026-17753: Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17742P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17742 [MEDIUM] CWE-346 CVE-2026-17742: Insufficient policy enforcement in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote Insufficient policy enforcement in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17815P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17815 [MEDIUM] CWE-346 CVE-2026-17815: Insufficient policy enforcement in GuestView in Google Chrome prior to 151.0.7922.72 allowed a remot Insufficient policy enforcement in GuestView in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17733P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17733 [MEDIUM] CWE-346 CVE-2026-17733: Inappropriate implementation in QUIC in Google Chrome on Android prior to 151.0.7922.72 allowed a re Inappropriate implementation in QUIC in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17820P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17820 [MEDIUM] CWE-346 CVE-2026-17820: Insufficient policy enforcement in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote Insufficient policy enforcement in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17731P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17731 [MEDIUM] CWE-346 CVE-2026-17731: Inappropriate implementation in Autofill in Google Chrome on Android prior to 151.0.7922.72 allowed Inappropriate implementation in Autofill in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17829P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17829 [MEDIUM] CWE-346 CVE-2026-17829: Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remot Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-17928P4MEDIUMCVSS 4.3fixed in 151.0.7922.72≥ 151.0.7922.72, < 151.0.7922.722026-07-30
CVE-2026-17928 [MEDIUM] CWE-200 CVE-2026-17928: Inappropriate implementation in DataTransfer in Google Chrome prior to 151.0.7922.72 allowed a remot Inappropriate implementation in DataTransfer in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14045P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14045 [MEDIUM] CWE-20 CVE-2026-14045: Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowe Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14075P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14075 [MEDIUM] CWE-602 CVE-2026-14075: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 all Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2025-13637P4MEDIUMCVSS 4.3fixed in 143.0.7499.40≥ 143.0.7499.41, < 143.0.7499.412025-12-02
CVE-2025-13637 [MEDIUM] CWE-449 CVE-2025-13637: Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote a Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass download protections via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14020P4MEDIUMCVSS 4.3fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14020 [MEDIUM] CWE-20 CVE-2026-14020: Insufficient validation of untrusted input in WebXR in Google Chrome prior to 150.0.7871.47 allowed Insufficient validation of untrusted input in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
Google Chrome vulnerabilities | cvebase