cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL483HIGH2795MEDIUM2393LOW78UNKNOWN82

Vulnerabilities

Page 25 of 292
CVE-2026-13032P3CRITICALCVSS 9.6fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13032 [CRITICAL] CWE-416 CVE-2026-13032: Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacke Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-13028P3CRITICALCVSS 9.6fixed in 149.0.7827.197≥ 149.0.7827.197, < 149.0.7827.1972026-06-24
CVE-2026-13028 [CRITICAL] CWE-416 CVE-2026-13028: Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacke Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-11095P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11095 [CRITICAL] CWE-20 CVE-2026-11095: Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11113P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11113 [CRITICAL] CWE-20 CVE-2026-11113: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-11120P3CRITICALCVSS 9.6fixed in 149.0.7827.53≥ 149.0.7827.53, < 149.0.7827.532026-06-04
CVE-2026-11120 [CRITICAL] CWE-20 CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7 Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2026-14382P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14382 [CRITICAL] CWE-20 CVE-2026-14382: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14120P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14120 [CRITICAL] CWE-693 CVE-2026-14120: Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote at Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-15901P3CRITICALCVSS 9.6fixed in 150.0.7871.128≥ 150.0.7871.128, < 150.0.7871.1282026-07-20
CVE-2026-15901 [CRITICAL] CWE-416 CVE-2026-15901: Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to pote Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-14044P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14044 [CRITICAL] CWE-416 CVE-2026-14044: Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had co Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14109P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14109 [CRITICAL] CWE-602 CVE-2026-14109: Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote att Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14043P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14043 [CRITICAL] CWE-416 CVE-2026-14043: Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-3545P3CRITICALCVSS 9.6fixed in 145.0.7632.159fixed in 145.0.7632.160+1 more2026-03-04
CVE-2026-3545 [CRITICAL] CWE-20 CVE-2026-3545: Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14411P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.46, < 150.0.7871.462026-07-01
CVE-2026-14411 [CRITICAL] CWE-20 CVE-2026-14411: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14037P3CRITICALCVSS 9.6fixed in 150.0.7871.47≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14037 [CRITICAL] CWE-693 CVE-2026-14037: Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote atta Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11638P3CRITICALCVSS 9.6fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11638 [CRITICAL] CWE-416 CVE-2026-11638: Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to pot Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2026-11654P3CRITICALCVSS 9.6fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11654 [CRITICAL] CWE-416 CVE-2026-11654: Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote att Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-5290P3CRITICALCVSS 9.6fixed in 146.0.7680.177≥ 146.0.7680.178, < 146.0.7680.1782026-04-01
CVE-2026-5290 [CRITICAL] CWE-416 CVE-2026-5290: Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2026-14095P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14095 [CRITICAL] CWE-20 CVE-2026-14095: Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-14093P3CRITICALCVSS 9.6fixed in 150.0.7871.46≥ 150.0.7871.47, < 150.0.7871.472026-06-30
CVE-2026-14093 [CRITICAL] CWE-416 CVE-2026-14093: Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had com Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2026-11671P3CRITICALCVSS 9.6fixed in 149.0.7827.103≥ 149.0.7827.103, < 149.0.7827.1032026-06-09
CVE-2026-11671 [CRITICAL] CWE-416 CVE-2026-11671: Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to p Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
Google Chrome vulnerabilities | cvebase