cbcvebase.

Google Chrome vulnerabilities

5,831 known vulnerabilities affecting google/chrome.

Total CVEs
5,831
CISA KEV
75
actively exploited
Public exploits
88
Exploited in wild
87
Severity breakdown
CRITICAL498HIGH2799MEDIUM2453LOW79UNKNOWN2

Vulnerabilities

Page 259 of 292
CVE-2023-5478P4MEDIUMCVSS 4.3fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5478 [MEDIUM] CVE-2023-5478: Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2022-4185P4MEDIUMCVSS 4.3fixed in 108.0.5359.71≥ unspecified, < 108.0.5359.712022-11-30
CVE-2022-4185 [MEDIUM] CVE-2022-4185: Inappropriate implementation in Navigation in Google Chrome on iOS prior to 108.0.5359.71 allowed a Inappropriate implementation in Navigation in Google Chrome on iOS prior to 108.0.5359.71 allowed a remote attacker to spoof the contents of the modal dialogue via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2011-2835P4MEDIUMCVSS 6.8fixed in 14.0.835.1632011-09-19
CVE-2011-2835 [MEDIUM] CWE-362 CVE-2011-2835: Race condition in Google Chrome before 14.0.835.163 allows attackers to cause a denial of service or Race condition in Google Chrome before 14.0.835.163 allows attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the certificate cache.
nvd
CVE-2022-3443P4MEDIUMCVSS 4.3fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3443 [MEDIUM] CVE-2022-3443: Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a re Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-3846P4MEDIUMCVSS 4.3fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-04-17
CVE-2024-3846 [MEDIUM] CVE-2024-3846: Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote att Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2020-16031P4MEDIUMCVSS 4.3fixed in 87.0.4280.66≥ unspecified, < 87.0.4280.662021-01-08
CVE-2020-16031 [MEDIUM] CWE-1021 CVE-2020-16031: Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2022-3444P4MEDIUMCVSS 4.3fixed in 106.0.5249.62≥ unspecified, < 106.0.5249.622022-11-01
CVE-2022-3444 [MEDIUM] CWE-20 CVE-2022-3444: Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a re Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a crafted HTML page and malicious file. (Chromium security severity: Low)
nvd
CVE-2023-5486P4MEDIUMCVSS 4.3fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5486 [MEDIUM] CVE-2023-5486: Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attac Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-5485P4MEDIUMCVSS 4.3fixed in 118.0.5993.70≥ 118.0.5993.70, < 118.0.5993.702023-10-11
CVE-2023-5485 [MEDIUM] CWE-79 CVE-2023-5485: Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote at Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4907P4MEDIUMCVSS 4.3fixed in 117.0.5938.62≥ 117.0.5938.62, < 117.0.5938.622023-09-12
CVE-2023-4907 [MEDIUM] CVE-2023-4907: Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4900P4MEDIUMCVSS 4.3fixed in 117.0.5938.62≥ 117.0.5938.62, < 117.0.5938.622023-09-12
CVE-2023-4900 [MEDIUM] CVE-2023-4900: Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allow Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4903P4MEDIUMCVSS 4.3fixed in 117.0.5938.62≥ 117.0.5938.62, < 117.0.5938.622023-09-12
CVE-2023-4903 [MEDIUM] CVE-2023-4903: Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.6 Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4364P4MEDIUMCVSS 4.3fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4364 [MEDIUM] CVE-2023-4364: Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4365P4MEDIUMCVSS 4.3fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4365 [MEDIUM] CVE-2023-4365: Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4360P4MEDIUMCVSS 4.3fixed in 116.0.5845.96≥ 116.0.5845.96, < 116.0.5845.962023-08-15
CVE-2023-4360 [MEDIUM] CVE-2023-4360: Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attac Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2020-16032P4MEDIUMCVSS 4.3fixed in 87.0.4280.66≥ unspecified, < 87.0.4280.662021-01-08
CVE-2020-16032 [MEDIUM] CWE-1021 CVE-2020-16032: Insufficient data validation in sharing in Google Chrome prior to 87.0.4280.66 allowed a remote atta Insufficient data validation in sharing in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2024-2629P4MEDIUMCVSS 4.3fixed in 123.0.6312.58≥ 123.0.6312.58, < 123.0.6312.582024-03-20
CVE-2024-2629 [MEDIUM] CVE-2024-2629: Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to pe Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-3844P4MEDIUMCVSS 4.3fixed in 124.0.6367.60≥ 124.0.6367.60, < 124.0.6367.602024-04-17
CVE-2024-3844 [MEDIUM] CWE-358 CVE-2024-3844: Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2024-2631P4MEDIUMCVSS 4.3fixed in 123.0.6312.58≥ 123.0.6312.58, < 123.0.6312.582024-03-20
CVE-2024-2631 [MEDIUM] CWE-451 CVE-2024-2631: Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacke Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-5858P4MEDIUMCVSS 4.3fixed in 119.0.6045.105≥ 119.0.6045.105, < 119.0.6045.1052023-11-01
CVE-2023-5858 [MEDIUM] CWE-346 CVE-2023-5858: Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a r Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
Google Chrome vulnerabilities | cvebase