cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 258 of 292
CVE-2016-1640P4MEDIUMCVSS 4.3≤ 48.0.2564.1162016-03-06
CVE-2016-1640 [MEDIUM] CWE-17 CVE-2016-1640: The Web Store inline-installer implementation in the Extensions UI in Google Chrome before 49.0.2623 The Web Store inline-installer implementation in the Extensions UI in Google Chrome before 49.0.2623.75 does not block installations upon deletion of an installation frame, which makes it easier for remote attackers to trick a user into believing that an installation request originated from the user's next navigation target via a crafted web site.
nvd
CVE-2018-18357P4MEDIUMCVSS 4.3fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18357 [MEDIUM] CVE-2018-18357: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2018-18355P4MEDIUMCVSS 4.3fixed in 71.0.3578.80≥ unspecified, < 71.0.3578.802018-12-11
CVE-2018-18355 [MEDIUM] CVE-2018-18355: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2021-30537P4MEDIUMCVSS 4.3fixed in 91.0.4472.77≥ unspecified, < 91.0.4472.772021-06-07
CVE-2021-30537 [MEDIUM] CWE-863 CVE-2021-30537: Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote a Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass cookie policy via a crafted HTML page.
nvd
CVE-2011-0780P4MEDIUMCVSS 6.8fixed in 9.0.597.842011-02-04
CVE-2011-0780 [MEDIUM] CVE-2011-0780: The PDF event handler in Google Chrome before 9.0.597.84 does not properly interact with print opera The PDF event handler in Google Chrome before 9.0.597.84 does not properly interact with print operations, which allows user-assisted remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2019-13761P4MEDIUMCVSS 4.3fixed in 79.0.3945.79≥ unspecified, < 79.0.3945.792019-12-10
CVE-2019-13761 [MEDIUM] CVE-2019-13761: Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2010-2645P4MEDIUMCVSS 6.8fixed in 5.0.375.992010-07-06
CVE-2010-2645 [MEDIUM] CVE-2010-2645: Unspecified vulnerability in Google Chrome before 5.0.375.99, when WebGL is used, allows remote atta Unspecified vulnerability in Google Chrome before 5.0.375.99, when WebGL is used, allows remote attackers to cause a denial of service (out-of-bounds read) via unknown vectors.
nvd
CVE-2021-21228P4MEDIUMCVSS 4.3fixed in 90.0.4430.93≥ unspecified, < 90.0.4430.932021-04-30
CVE-2021-21228 [MEDIUM] CWE-863 CVE-2021-21228: Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an atta Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2019-13710P4MEDIUMCVSS 4.3fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13710 [MEDIUM] CVE-2019-13710: Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allow Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.
nvd
CVE-2023-5851P4MEDIUMCVSS 4.3fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5851 [MEDIUM] CWE-346 CVE-2023-5851: Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2019-13704P4MEDIUMCVSS 4.3fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13704 [MEDIUM] CWE-290 CVE-2019-13704: Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remot Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2018-6178P4MEDIUMCVSS 4.3fixed in 68.0.3440.75≥ unspecified, < 68.0.3440.752019-01-09
CVE-2018-6178 [MEDIUM] CWE-1021 CVE-2018-6178: Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.
nvd
CVE-2023-2937P4MEDIUMCVSS 4.3fixed in 114.0.5735.90≥ 114.0.5735.90, < 114.0.5735.902023-05-30
CVE-2023-2937 [MEDIUM] CWE-451 CVE-2023-2937: Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-2938P4MEDIUMCVSS 4.3fixed in 114.0.5735.90≥ 114.0.5735.90, < 114.0.5735.902023-05-30
CVE-2023-2938 [MEDIUM] CWE-451 CVE-2023-2938: Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-6511P4MEDIUMCVSS 4.3fixed in 120.0.6099.62≥ 120.0.6099.62, < 120.0.6099.622023-12-06
CVE-2023-6511 [MEDIUM] CVE-2023-6511: Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2019-13715P4MEDIUMCVSS 4.3fixed in 78.0.3904.70≥ unspecified, < 78.0.3904.702019-11-25
CVE-2019-13715 [MEDIUM] CWE-290 CVE-2019-13715: Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2022-2165P4MEDIUMCVSS 4.3fixed in 103.0.5060.53≥ unspecified, < 103.0.5060.532022-07-28
CVE-2022-2165 [MEDIUM] CVE-2022-2165: Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a rem Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2011-2599P4MEDIUMCVSS 4.3v112011-06-30
CVE-2011-2599 [MEDIUM] CWE-200 CVE-2011-2599: Google Chrome 11 does not block use of a cross-domain image as a WebGL texture, which allows remote Google Chrome 11 does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.
nvd
CVE-2023-2466P4MEDIUMCVSS 4.3fixed in 113.0.5672.63≥ 113.0.5672.63, < 113.0.5672.632023-05-03
CVE-2023-2466 [MEDIUM] CVE-2023-2466: Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote att Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2019-5838P4MEDIUMCVSS 4.3fixed in 75.0.3770.80≥ unspecified, < 75.0.3770.802019-06-27
CVE-2019-5838 [MEDIUM] CWE-863 CVE-2019-5838: Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.
nvd
Google Chrome vulnerabilities | cvebase